VOOZH about

URL: https://thenewstack.io/chainguard-takes-over-maintenance-of-aging-oss-projects/

⇱ Chainguard Takes Over Maintenance of Aging OSS Projects - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2025-12-16 06:00:23
Chainguard Takes Over Maintenance of Aging OSS Projects
Open Source / Software Development

Chainguard Takes Over Maintenance of Aging OSS Projects

With EmeritOSS, Chainguard provides security maintenance for mature OSS after the original maintainers leave, starting with Kaniko, Kubeapps, and ingress-nginx.
Dec 16th, 2025 6:00am by Darryl K. Taft
👁 Featued image for: Chainguard Takes Over Maintenance of Aging OSS Projects
Featured image by Getty Images for Unsplash+.

Chainguard today announced Chainguard EmeritOSS, its new model for supporting mature open source projects and long-term open source software (OSS) sustainability for the community.

“We’re creating a stable and predictable home for projects that have reached this stage,” wrote Erin Glass, staff product manager, Dan Lorenc, CEO and co-founder, and Kim Lewandowski, CSO and co-founder, in a blog post.

Mature OSS projects often remain embedded in production systems after maintainers move on. In an interview with The New Stack, Lorenc mentioned last year’s xz-utils incident — where a backdoor was nearly introduced after the 20-year maintainer wanted to retire — exemplifies the risks when there’s no safe transition path.

“Last year’s xz-utils incident demonstrated how severe the consequences can be when there’s no clear path for maintainers to step away safely,” the Chainguard post reads. “When the original maintainer wanted to retire after 20 years of commitment to the project, a new contributor gradually gained trust and then nearly introduced a sophisticated backdoor that could have compromised countless systems across the industry.”

Indeed, many open source projects fall into a gray area between active development and complete abandonment, Chainguard said. “They’re stable and widely used but still need minimal maintenance for security patches, dependency updates, and compiler upgrades. When maintainers move on, these projects can become security risks.”

Kaniko Was First

“In June 2025, when Google announced it was archiving the Kaniko project, some of our customers reached out to tell us how disruptive the change was to their workflows,” Chainguard said. “We stepped in with maintenance-only support on our fork of Kaniko to help them safely use or transition away from Kaniko.”

Kaniko is part of the EmeritOSS program.

I covered that news and wrote: “Kaniko, a tool that enables building Docker images inside Kubernetes clusters without privileged containers, has become foundational infrastructure for organizations across financial services, defense, and other regulated industries.”

Today, Chainguard said, “With Kaniko, we’ve already delivered CVE [common vulnerabilities and exposures] fixes, dependency updates, and maintained images to keep customer workloads running safely during their migration period.”

In addition, today Chainguard added two additional inductees into the EmeritOSS program: Kubeapps and ingress-nginx, two tools whose maintainers have reached natural life cycle transitions. As part of the program, Chainguard is enabling these projects to stay secure and operational for teams who depend on them.

“Having the possibility to get a supported ingress-nginx allows us to spend more time to evaluate the plan to move teams to another ingress controller or gateway API,” said Louis Gisarov, DevOps manager at Rogers Communications, in a statement. “Chainguard’s decision to take on the maintenance of ingress-nginx gives us confidence that we can continue to operate securely. It’s great to see an organization step in to support critical OSS in a way that respects maintainers and protects users at the same time.”

“Our forked, stability-focused versions will remain freely available on GitHub in source form only,” Chainguard said. “Organizations that prefer a secure, continuously maintained container image or APK can opt for our commercial distribution.”

Chainguard EmeritOSS Team

Chainguard has initially established a team of two to three people to work on the EmeritOSS program, Lorenc said.

“We’re experimenting now just to see how big we can scale this. Because the work is bursty. Some months, some quarters, some years, there might be zero work for any given project. Other times, it’s going to get busy,” he told The New Stack. “So, we kind of want to push the limits to see how many of these projects a small team can actually do this for and then figure out what it’ll look like as we start to scale it up.”

Although the team is starting small to test the model before scaling, it is leveraging Chainguard’s existing automation infrastructure for vulnerability patching and using AI tools to scale support across potentially hundreds or thousands of projects, Lorenc said.

Filling the Gap

Without a structured transition model, organizations that depend on these mature projects are left vulnerable. EmeritOSS helps fill this gap. It provides a secure, stability-focused safe landing for essential open source projects that don’t need new features but do require ongoing care, Lorenc said.

According to the blog post, Chainguard offers various levels of support depending on community expectations and the project’s life cycle, including:

  • “Creating a public fork of the project to preserve ongoing access to the codebase. These are not hostile forks — our goal is continuity, not competition.
  • “Updating dependencies to fix vulnerabilities and creating new releases with the updates.
  • “Publishing clear documentation outlining support scope and service levels.
  • “Building EmeritOSS projects from source and adding them to our image catalog when needed, along with updated APK packages where applicable.”

Chainguard will not support new feature development or proactively engage with community issues or pull requests because these projects are mature and don’t require it. “Our job is to keep them safely in that state,” Lorenc said.

However, “Our forked, stability-focused versions will remain freely available on GitHub in source form only. Organizations that prefer a secure, continuously maintained container image or APK can opt for our commercial distribution,” the Chainguard post said.

“These are not hostile forks — our goal is continuity, not competition,” Lorenc said.

Meanwhile, Lorenc summed up the goal of the EmeritOSS program: “There are two kinds of projects out there, ones where you care what version number you’re on, and ones where you don’t know what version number you’re on. And this is for the latter.”

Chainguard frames this as part of their broader OSS commitment, citing their Sigstore on-call work and GitHub Secure Open Source Fund contributions.

“I think over time, this is probably something some foundation should try to pick up, but we want to prove it works before we do something like that,” Lorenc said. “You know, we’re chatting with folks like the Linux Foundation and other groups to see if this makes sense long term.”

TRENDING STORIES
Darryl K. Taft covers DevOps, software development tools and developer-related issues from his office in the Baltimore area. He has more than 25 years of experience in the business and is always looking for the next scoop. He has worked...
Read more from Darryl K. Taft
SHARE THIS STORY
TRENDING STORIES
Chainguard is a sponsor of The New Stack.
TNS owner Insight Partners is an investor in: Docker.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.