Open Community Experience (OCX)

Be careful what you wish for: Your project might become infrastructure

32:15 · 21 Apr 2026 – 23 Apr 2026 · YouTube

About this talk

This talk addresses the evolution of Open VSX, a community project that transformed into a critical infrastructure as its usage rapidly expanded. The speakers, Tabang Masho and Gel Blonde, explain how Open VSX was initially created to solve a specific problem within the Eclipse Foundation ecosystem by providing vendor-neutral access to VS Code extensions. As dependency on the platform increased, the project's management shifted from a best-effort community service to a more structured, resilient, and performance-oriented operation. They discuss the need for security measures to handle malicious content and emphasize the importance of communication and expectations in this transition. The speakers highlight the project's growth, the implementation of SLAs, and the necessity of adapting to serve an expanding user base adequately.

Full transcript

Okay, welcome everyone. Good afternoon. Um, I'm Tabang Masho and this is Gel Blonde. Our talk this afternoon is about a happy or fortunate problem to have is if your community project ends up becoming critical infrastructure. So, and um obviously the title is a bit tongue andcheek, but it really reflects what um what can happen if you get adopted at a scale that you're not prepared for. So

we'll be using open VSSX as a concrete example of something that happens to a lot of projects where you start solving a very practical problem for a community and then one day you realize not only are people using the project but they're depending on it. There's a real critical dependency on that technology or that project and that's when the job changes and when the real fun begins.

And uh and With that, let's uh let's proceed. So, in terms of the topics that we'll cover, first of all, why OpenVSX began in the first place. And as I say that, I look into the audience and I see people who uh created Open VSSX. So, uh I'm sure they'll keep me honest. Um, we'll also talk about how the the origins really changed and and once it

got used and adopted uh that shaped the uh the development of the technology and then Gel will talk uh and give us a sense of what happens technically and then we'll look at security and and also the broader lessons around stewardship. ship of the project. So to understand the current story you have to start at the original gap the problem that was uh what the problem that

was uh the uh the impetus for the technology and open VSSX wasn't created because someone or some people had a grand vision or theory about critical infrastructure and commercial dependencies but it was created because the ecosystem and specifically the community needed something that they did not have so and I'm quoting uh Miro who is in the audience today. Hopefully I do your words justice. But open VSSX

started as a specific practical solution to the problem that was presented by not being able to access VS Code extensions if you weren't a Microsoft branded product. the broader ecosystem was adopting VS code extensions and more tools needed to have access to that extension marketplace and that's really where open VSSX came from in the Eclipse Foundation context. Eclipse Thea and other projects needed a dependable way to

access these technologies at scale and that's where the practical community problem um or solution evolved in in the way of Open VSX. It wasn't a giant platform strategy and it was just a a real problem that needed to be solved. What Open VSSX provided was an open vendor neutral home for these VS Code extensions compatible extensions rather and it mattered to Feya as I mentioned to VS

Codium to Git Pod and to others it meant the ecosystem actually had something that it could build on and it wasn't just about compatible extensions it was about having a resource that was open, vendor neutral, reusable, and adaptable over time. Now, in the early days, the usage was much more human-driven. So, people searched, browsed, and installed in sections, sorry, installed extensions. The traffic could be bursty, and

expectations were closer to what you'd expect with a community service. To that end, when the Eclipse Foundation took over the uh management of of Open VSX as a as a registry, we really considered it as a background service and a best effort service at that. Now over time that changed as more systems began to use the registry continuously and that real shift wasn't just traffic it was

a real deeper dependency and that's where the story starts to evolve right that's where it starts to get interesting. So as more tools integrated and more workflows depended on it, once that happens, you're no longer just running something that's helpful, that's a best effort, that's a convenience. Uh you start to see businesses depend on it, venturebacked companies that are based on it and and enterprises that are

relying on it as a critical resource. So the bigger change was dependency. And in fact to speak to some of those examples. Um just a view of the the different platforms and tools that uh rely on the the package on the uh on the public registry. You have a who's who of open- source projects and and AI tools and cloud uh vendors, cloud ID vendors. You're seeing

more polling, more automation, and less tolerance for some of the um the attributes and behaviors of a best effort service. Uh no longer are you just having people browse the UI and clicking install once in a while. You're seeing ser systems and and behaviors that expected to be available continuously on demand and just looking at some of the numbers, right? So, um, we've seen growth, and I

think Mike actually spoke to this in his opening day keynote where now we're over 12,000 hosted extensions and counting. If you look at the year-over-year progression, it really does start to look like a hockey stick where now we're at 300 million downloads per month. Um, it took us a certain period of time to get to 15 50 million uh downloads per month. It took us another year

to get to 100 million and in roughly six weeks we went from 100 million to 300 million in counting. Uh it it is an important resource not only for our community and ecosystem for the Eclipse Foundation ecosystem but as we see here uh for other communities and ecosystems and this growth continues uh practically unabated. And what that means is that availability is essential. Um performance, it has

to be highly performant and dependable. And then reliability and resilience are our table stakes. So, we had a critical moment uh in July of 2025 where we had an outage and it wasn't just something that affected us and some community members and and you know within the the walls so to speak of the Eclipse community, but you had people who came um uh literally out of the

woodwork because we weren't aware they're using uh OpenBSX who came and said, "Well, the system must be up. what are you doing to uh to ensure that it's up? And then we explained to them this is a comm community resource. It's a community supported and operated service and and that really highlighted the disconnect um between what we were able to do and what uh the expectations were.

And that started the journey that uh that uh capped off with the announcement this week about the managed registry where we were able to coalesce the types of involvement uh investment and participation to build the infrastructure that underpins that And with that, I'll hand off to Gail. >> Yeah. So, um it's it's kind of interesting that uh you have a project that starts as an open source

project. So we were talking about that with mirrors the other day like uh in 20 I think the project proposal was in 2019 and uh the very beginning of the project was uh yeah in the next uh next two years I would say and um like uh like Tabong just said um we more or less started this uh story by providing a a couple of virtual machines

so that uh Miro and the other type folks and and Gitbot at the time etc. and and a few other uh partners could operate something they needed. But for so many years it was just hey come on that's that's just we we were not even thinking about it and then the the critical moment the tipping point in when the we have this outage. So I know that

some some of you in in the room remember that like you said. Uh but then they they start to call us and say hey it must it must be online and it must uh we our business is depending on it which is kind of interesting moment because uh we when we do open source we never know who is using it and you never know when some people

are start start um start really uh doing stuff with it. So um say we we have very very different uh infrastructure expectations from uh the initial moment when you you put together just kind of a proof of con of concept or or demonstrator that hey uh open VSSX is something that is possible and uh if uh and because because that's that was well designed so API APIs

were were open and it was just a terms and condition of of uh the Microsoft marketplace that were for well that were um blocking for from using that in in others. So um having competing or on an independent marketplace was possible and that's that really started with with this uh low profile stuff that stayed kind of low profile for so much so long >> that I think

that I could say that in in our staff we we were we we maybe at some point forgot about it until uh we had to to to look at hey we have this kind of uh hockeyistic uh hockeyistic traffic. So that's going through the roof. We have uh the availability the expectations in terms of availability are people calling us or shouting at us saying hey we are

losing money because of you etc. And and that um you you cannot just put it online it's also uh making a kind of making a product uh out of it. So what does it means? It means of course uh moving to a more uh scalable uh architecture moving to also uh starting thinking uh differently like like we say here with resilience. So we know that we want

this to be rock solid and uh so we have to we are going to towards multi-reion resilience. We know that it's not just about that it's out there but we need to to implement monitoring uh and um and other and other observability uh aspects and ultimately we started also to to control how products were eating the project. So that was something that was put in place uh

well two three weeks two three weeks ago. >> Yes. Um and uh that's um that's really when as a result of uh thinking about oh we have we had an open source project but now we are we are moving from uh hosting an open source project having a working group around it which is of course our bread and butter but then we are moving to building a

product around it and it's kind of just like a fun fact we always tell people that you should have a different name for the open source project for the working group for the product and well you know I think our the project is open >> yes >> the working group is open VSSX working >> and the product I think oh yeah it's also open VSSX >> say

maybe we could have done better we need to I mean I think we are losing credibility when we will tell people that you need different names but that's another story at least Um, we it's it's important to to to see that from an open source project point of view and we we everything we do we do it in the open source project but from an open source

project point of view having the rate the capability to to control the the rate of specific IP address coming to the marketplace does not necessarily make sense. But when you want to build a product and when you want to be able to monetize access to the big players you saw you you saw on the previous slide you absolutely need that um because otherwise uh they will say

oh yeah no problem we are we are friendly etc. But that's that's really this uh this moment when the value proposition is that okay you have those many requests per second in a sustained way and and that's we commit we we provide the guarantee that we will deliver that to you. that's uh something completely new for us and I think we are still uh learning we are

still in in in the learning curve but uh but again uh that's uh serving the traffic is one part and uh serving um extensions is an interesting business because of course when you look at the the marketplace traffic the Marketplace traffic by itself is just API calls etc. But then you have to deliver the the blob. So we had to put in place uh CDN uh and

all that stuff. Um recovering well uh making sure that uh when when something uh happens when we have something unexpected we can uh process it. we can uh manage it and we can continue operations because uh something also completely new for us is that we are now selling SLAs and so uh it's a lot of engineering technical engineering legal engineering and then uh in addition to the

to the product >> financial engineering >> financial engineering um and so that's all that stuff that we we had to we had to learn and um oops Yeah, sorry. Um and then um we realized open source uh is good. Uh extensible systems like uh open VSSX extensions like VSSX VS code extensions are good. But uh of course you you read the news and you know that some

people uh want to use those systems to attack people and and more or less to to try to get their bitcoins and other cryptos etc. So it's amazing that uh at some point security became a very very hot topic and we were lucky to some extent we were pretty well equipped to to work on the on the security side but uh still we had to to adjust

what we have in the project and how we operate around it because to to just be able to to to get rid of all the malicious extensions. that we're trying to to come to to our project. So that was a a huge development uh in the project to to make sure that publication is uh curated. So we have a autom automatically we are automatically uh checking for

namespace have used we are automatically uh trying to to spot we are we are running uh uh antivirus uh for malicious uh malicious code detectors on all the on on all the the extensions and also stuff like namespace abuse which is uh something that is uh very common and uh well we have not only the the software had to be adjusted but also the team by itself

uh we have uh people who every day would go looking at what we have in quarantine and decide what we should do Should we should we accept it? Should we should we just uh uh throw it to to garbage and and potentially even uh make announcement about the fact that uh we we we need to to remove this this extension etc. Interestingly on that front um we

were not better or we were we were not better or less well equipped than our friends of uh of Microsoft. I think that we we had a we had a a lot of uh conversations at some point with them that uh and we started to to collaborate uh bit with them on the topic because they knew that uh we some some stuff that we were seeing they

were also seeing it and uh we we had all legitimate interest in in working together. Um also one thing we you didn't mention it but uh maybe uh it's interesting to mention it is that uh over the last uh few weeks and months we have observed that initially everybody was publishing to Microsoft marketplace first >> and that then some people most people were publishing to uh open

VSSX and now they are coming to us uh some of some of them are publishing to us first which is kind of an achievement. >> Yeah, it's a fascinating um turn of events where open VSSX so again this project and service now that has these humble origins has become the destination and distribution channel of choice for these agentic AI development tools. So for a whole ecosystem uh

and and that in itself is is fascinating. I think there's a few reasons why that's the case. Uh the vendor neutrality, the fact that everyone can come and it's a level playing field um that's backended and stewarded by the Eclipse Foundation. I think that really gives people the assurance that hey uh there's a an honest broker in the mix uh in in the way of the Eclipse

Foundation. And then as Guy mentioned, we have become a target like any other um extension marketplace, packet registry and and we've had to adjust and we've we've taken actions that uh are inspiring trust. So everyone knows that security vulnerabilities are proliferating and it's getting worse and worse. It's a multi-t trillion dollar or euro business. But the fact that we're actually taking steps uh as Guy mentioned on

a proactive basis and folks in the audience may know that we launched um a uh researcher reward program, reward and recognition program. All of these things matter and people see that uh that we're we're trying to partner and and collaboratively ensure that this is a uh trusted and safe shouldn't say safe a trusted environment. >> Yeah. Because ultimately everything we do in terms of uh creating trust

in terms of uh instrumenting the tooling for for security etc is also stuff that we do because we don't want to to make the headlines in the news that uh that that uh there was a big problems in the open VSSX registry. I think that u now to be fair I think we'll make the headlines regardless. So if you Google open VSSX and news, you'll see that

there's probably some security vulnerability uh uh that's being written about every day. >> Sure. >> But but I think that's balanced with the fact that we're we're really as an ecosystem, we're we're trying to as a community, we're trying to take these steps. >> Yep. >> So yeah. So what does this all add up to? Right. So, a lot of headaches, maybe regret, did we do the

wrong thing? Um, uh, I think it it adds up to learning, right? And embracing the, uh, the change and dynamics that, you know, for many of us attracted us to to technology and in particular open source in the first place, right? um being able to ship, deliver good code that solves a problem in the world and then as the adoption grows, as the the uh the demands

grow, being able to uh to to adapt accordingly and what we've seen is that u you know as these uh as these changes have happened, Gle mentioned that that the organ organization has changed as well. So we have uh at the eclipse foundation we maybe had half a half half a person. So uh 0.5 of a full-time equivalent resource uh providing support to to open VSSX and

now that's grown to over a dozen dozen folks. So again this is um this is you know what you see when in our case we've we've productized the the project and and I think similarly the analogy is that if you have a hugely successful project you're going to have to depend on more maintainers on more committers and contributors right so that's uh probably an apt analogy especially

when you're running something that other people depend on uh the nature of the network changes right so more discipline is required right so uh we talked about SLAs's and and uh the types of commercial guarantees that we are providing at the Eclipse Foundation but just take you know an analogous or analogous uh project right if more people are depending on it um I think we've seen uh

we've experienced firsthand many of us in the room here these competing pressures right you actually want people to be using and adopting your technology, your your project, but then it shouldn't be weighted uh in a way where as a as a contributor or as a committer, you feel like you're you're working for someone, right? You'd rather be working with someone, right? So, I think that's that's certainly

something that we all need to contend with. And I think a critical uh element of that is communication, right? So setting expectations as to uh what the not only the scope of the project is but how you will engage with those various stakeholders and it's also okay you know to draw the line before before we went down this journey of of creating the uh managed registry so

a service offering based on opensx we were at the point of saying you know what this is best effort take it or leave it and I think it made some kind of sense to us to make these investments, but then as project maintainers and contributors, that needs to be at least a decision point and a discussion that people have um as to how they're approaching it. Gale.

>> Yeah. Well, so uh also one thing I I I wanted to to add is that um you may wonder why as a foundation we start producing products because you may think that okay the foundation has always told us that we are here to support uh open source projects and support working groups etc but uh I think that uh it's perfectly makes sense that uh we we

position ourself as a product provider for such an infrastructure. So that's uh because really um what we provide here we are in this position to provide it because we are a trusted partner and and because we are trusted partners that will provide the same service to the different stakeholders and so they come to us knowing that we will not change terms of of and conditions and on

our side what what it means also um that uh this move that you just described very well that uh okay this is open source we are not your we are not your provider and indeed we move from the we are not your provider uh stance to hey we are your provider we can be your provider of this uh infrastructure but that has a cost and you need

to help us sustain this world uh community if you want it to be sustain to if you want it to be sustainable because that's uh part of the of the drama and when when we say that it becomes an infrastructure. You may have read some uh open letter from other open source foundations or so and and we were signatory of that which is that yeah well the

world is building on open source components. The world is building everything on open source uh package managers on open source uh infrastructures and nobody is really uh thinking about how to maintain this them and we are lucky here that uh we we found a business model that we we are we start so we announced with three launch partners launch customers and and uh we have a we

have a few more that are very very close to closing. Um so we are lucky that we managed to to put together this uh this business model that makes it sustainable because of course what we did uh six years ago to just have something that was uh here now having those those this dozen person working working on the project to to just implement this uh operating model

and to uh to to make sure that the service is always there. It's something that uh that has a very different cost structure and to some extent you you know we all know the the famous uh the tragedy of the commons and I think that what we can be uh proud of in uh in this is that we fix the tragedy of the comments. Oh well let

me let me be optimistic. Okay, we are we are we have found a model that we think fixes the tragedy of the comments for uh open VSSX extensions and uh but uh we we do that by sticking to our values of being an open source foundation that is supporting the open source ecosystem. So the open source project all the development is still uh doing done in in

the open source project. Uh the working group is still the place where different stakeholders can collaborate and we do we have this uh uh reference u uh marketplace that is uh indeed a product and we treat it like a product but is also sustaining all the developments for the rest and that is also not competing with some members uh who are using it here here and there

for private marketplaces for example. Yeah. So just um another option about the title of this talk was that uh beware what you are asking for because maybe your project maybe been become widely successful almost by accident because I think that I don't know maybe Miro and and you and your friends you had a this uh master plan from the beginning and you you you were knowing that

it would become so successful successful, but I don't think so. But the fact that you you you guys started it because you you needed it for a specific use case and um and at some point when everybody started to fork VS Code and needed to have access to a to an extension uh marketplace, >> it was just there. So everybody started to use it and some people

of course use it with more success than others because when you have a a project like anti-gravity that is coming on the market I think that we immediately saw that on on the >> on the on the request number of requests we received per day but then um it's it's really uh well the good news is that we managed to to pivot our organation and to and

to move from this uh yeah we are an open source steward to yes we can put together a product and be a steward of this this uh marketplace >> and if I can just underline that point because I've been speaking to a lot of you and also people in the press and the question keeps on coming up well why did you do this thing and that last

thing that gel said is is critically important which is that we view this as part of our stewardship Right. So it I think it maybe it was around the uh American or global banking crisis where they said it's too big to fail. I think open VSSX had gotten to a point where it was too big to fail. And we um we felt and we continue to feel

managed registry and operating model, this financial model is is core to the sustainability not only of the service but ensuring that the project and the working group have the resources that they need to be successful.