VOOZH about

URL: https://thenewstack.io/put-a-fork-in-it-the-future-of-open-source-thats-done/

⇱ Put a Fork in It: The Future of Open Source That’s 'Done'  - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2025-12-16 09:30:56
Put a Fork in It: The Future of Open Source That’s 'Done' 
sponsor-chainguard,sponsored-post-contributed,
CI/CD / Containers / Open Source

Put a Fork in It: The Future of Open Source That’s ‘Done’ 

If working in OSS sometimes feels like running on a treadmill, then “done” software is the rare moment when the pace finally eases.
Dec 16th, 2025 9:30am by Dan Lorenc
👁 Featued image for: Put a Fork in It: The Future of Open Source That’s ‘Done’ 
Image from Mauro Pezzotta on Shutterstock.
Chainguard sponsored this post.

Working in open source software (OSS) sometimes feels like running on a treadmill that never stops. The projects you depend on keep moving, but if you miss a step, you get flung off the back. For many developers, it’s an endless race to keep up with shifting dependencies, urgent common vulnerabilities and exposures (CVEs) and new features.

But not all open source moves at that speed. It exists on a spectrum from fast-moving, feature-rich projects to quietly abandoned ones. In between lies the most overlooked category: software that is simply “done” and ready to graduate into long-term stewardship.

“Done” software should be celebrated. It finally lets developers step off the treadmill without worrying that the ground will shift beneath them.

The Underrated Value of ‘Done’ Software

Not every open source project requires a sprint forever. Some reach a point where the core functionality is complete, the design is stable and the user base is satisfied. “Done” projects become quiet infrastructure that’s dependable and predictable, and only requires occasional maintenance.

Ingress-nginx is an example of a project that was “done” long before the community realized it. It’s one of the most popular open source ingress controllers for Kubernetes, powering billions of requests in data centers and home labs all around the world. Despite its massive adoption, the project never had more than one or two maintainers who contributed to it in their spare time. Just last month, the Kubernetes community announced its decision to archive the project in March 2026.

When a project reaches the “done” phase, it’s an achievement. The code is stable, the design is sound and the community relies on it. These projects are the foundation of a healthy, long-lasting ecosystem, which means they still need occasional upkeep so the community that depends on them can use them securely.

Scaling Support for ‘Done’ Projects 

A surprising number of open source projects today have only one or very few maintainers. When that maintainer wants to step away, people still depend on the project, but no one is formally responsible for its long-term care.

Last year’s xz-utils incident showed us what happens when there isn’t a path for handing off projects safely. When xz-utils’ original maintainer — an individual who had dutifully managed its upkeep for 20 years — wanted to step away, a new contributor gradually earned trust, only to nearly slip in a sophisticated backdoor. If that attack had succeeded, it could have taken down almost every major system.

We need a way for open source maintainers to gracefully hand off “done” projects even when they no longer have a significant feature roadmap. We need to offer them a place where:

  • Mature projects can transition from individual maintainers to a trusted organization accountable for long-term stewardship.
  • CVEs get patched continuously, even without new feature work.
  • Reproducibility and trust remain, without weekly commits.

This graduation should signal that the project is stable, valuable and ready for a long life supported by shared responsibility.

Forks Are a Critical Strength of Open Source

Putting a fork in abandoned software is how the community can bring it back to a “done” state. Kaniko is one of the clearest examples of this. When Chainguard forked and took over its maintenance, we inherited a tool that was already doing its job well, which thousands of people relied on. We stepped into the role of long-term custodians for something that was effectively complete. Kaniko required predictable, responsible oversight with occasional updates and minor patches every year. It didn’t need new features. Today, when teams want new features, they can fork Kaniko from a trusted source and build those features themselves.

Forks offer a path for teams to build on a stable foundation without disrupting the project’s core purpose. They preserve user choice, prevent burnout and allow innovation without destabilizing the core. Most importantly, they ensure that open source remains open and free to evolve wherever the community needs it to go.

Building a Sustainable Path Forward

Open source will always have projects that sprint forward and projects that fall behind, but the future of a healthy ecosystem is ensuring mature software has a safe place to land. By establishing graduation paths for “done” software, empowering maintainers to step away safely and encouraging organizations to take on long-term custodial roles, we can prevent the next xz-utils scare.

If working in OSS sometimes feels like running on a treadmill, then “done” software is the rare moment when the pace finally eases. By embracing sustainable stewardship and welcoming forks as part of the open source life cycle, we can build a future where stepping off the treadmill is a sign of success, not failure.

Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk.
Learn More
The latest from Chainguard
Hear more from our sponsor
TRENDING STORIES
Dan Lorenc is co-founder and CEO of software supply chain security company Chainguard. Dan has been working on and worrying about containers since 2015 as an engineer and manager. He started projects like Minikube, Skaffold and Kaniko to make containers...
Read more from Dan Lorenc
Chainguard sponsored this post.
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.