Explore the hidden economic and security costs of running open source package registries and why commercial stakeholders must help sustain this critical infrastructure.