Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteThe OpenJS Foundation announced its Ecosystem Sustainability Program (ESP) on May 21, 2024. It is an opt-in partnership framework in which commercial providers offer security fixes and support for archived, end-of-life, or otherwise older OpenJS project versions, while participating projects receive a share of the resulting revenue. HeroDevs was the first named provider.
What the Ecosystem Sustainability Program does
ESP addresses a common problem: an organization may still depend on an OpenJS-hosted software version after normal maintenance has ended. OpenJS encourages migration to a currently supported release, but the program provides a commercial-support route when an immediate move is not practical.
Under the model, an approved provider sells security-fix and support services for eligible legacy versions. A participating project opts in and receives revenue that can fund maintenance and other project work. The May 2024 announcement described the arrangement as revenue sharing based on enterprise sales.
OpenJS said the sustainability rationale included the fact that 52% of its contributors were affiliated with an organization, according to the Foundation’s 2024 figure. The announcement did not provide survey methodology, so that number should not be treated as a general industry statistic.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Who can participate
Provider requirements announced at launch
- Gold or Platinum membership in the OpenJS Foundation.
- Co-marketing under a trademark-license agreement.
- Endorsement or sponsorship from the relevant project technical steering committee or core team, where applicable.
- Endorsement or sponsorship from the OpenJS Cross Project Council.
OpenJS announced HeroDevs as the inaugural provider. A March 20, 2024 Foundation announcement said HeroDevs had joined at Gold level and offered business security and compliance products, consulting, engineering, and help migrating from deprecated packages.
Project requirements in the maintained guidance
The maintained ESP guidance describes participation as opt-in. A project must:
Rank #2
- Have a partner that provides support for its end-of-life versions.
- Agree to place partner links on pages or repositories where end-of-life versions are mentioned.
- Manage program funds through Open Collective.
Projects interested in joining are directed to contact OpenJS support. The guidance recommends a clearly labeled version-support page, prominent partner links near the top of that page, and links to partner pages for the versions covered. OpenJS supplies project-specific referral links during onboarding.
It also suggests placing a prominent homepage banner three to 12 months before a version reaches end of life. Payments are described as semiannual. When Open Collective is used as fiscal host, the guidance says it charges a 10% fee on incoming funds; operational details can change, so participating projects should verify the live guidance.
What HeroDevs’ terms were in the 2024 launch announcement
The May 21, 2024 announcement said HeroDevs would contribute 15% of revenue to every participating OpenJS Foundation project and publish notifications for discovered CVEs. Those are terms attributed to the launch announcement, not independently verified current commercial terms. The maintained program guidance lists HeroDevs as the current partner but does not restate that percentage.
The arrangement is intended to connect paid legacy support with project funding. It does not make an end-of-life release an officially maintained upstream version, and it does not remove an organization’s responsibility to plan a migration.
Express Never-Ending Support as the first project example
On October 10, 2024, OpenJS announced a partnership among Express and HeroDevs to launch Express Never-Ending Support (NES). The announcement described security patches, compatibility updates, and expert support for legacy applications.
Rank #4
That post said NES supported Express 3 at the time and planned to extend coverage to Express 4 once Express 4’s end of life was announced. This describes the scope reported on October 10, 2024, rather than a current availability guarantee. Organizations should confirm today’s Express version coverage directly before purchasing.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Choosing between migration and extended support
There are two practical paths for software running an unsupported OpenJS version. The right choice depends on risk, compatibility and timing rather than on a universal price or performance advantage; the cited announcements provide no pricing comparison or service benchmark.
Best Value
| Decision factor | Move to a supported version | Evaluate commercial extended support |
|---|---|---|
| Security coverage | Receives the normal maintenance policy for the supported release. | May provide security fixes for the specified legacy versions under a paid support agreement. |
| Compatibility | May require code, dependency, infrastructure, or testing changes. | Preserves more of the existing runtime while the covered version remains supported by the provider. |
| Timing | Requires a migration project and release planning. | Can provide an interim path when an immediate migration is not feasible. |
| Version scope | Determined by the currently supported OpenJS release policy. | Must be confirmed for the exact project and version; legacy coverage is not automatically broad. |
| Project sustainability | Reduces dependence on end-of-life code and follows OpenJS’s preferred direction. | Can generate revenue for an opted-in project through the ESP. |
Questions to answer before buying legacy support
- Which exact OpenJS project and version are deployed in production?
- What end-of-life date and security obligations apply to that version?
- Does the provider cover the runtime, dependencies, operating systems, and deployment environments you use?
- What constitutes a security fix, compatibility update, response-time commitment, and support term?
- How will the organization fund and schedule migration to a supported release?
What the program means for organizations
ESP gives organizations that cannot migrate immediately a way to seek commercial support while directing some associated revenue back to participating open-source projects. It should be treated as a risk-management bridge, not as a reason to defer modernization indefinitely. Confirm the provider, version scope, contract terms, and current OpenJS program guidance before relying on it.
Frequently Asked Questions
Is the ESP mandatory for OpenJS projects?
No. The maintained guidance describes it as an opt-in program, and projects must meet the participation conditions and work with a support provider.
Does ESP replace upgrading Express or another OpenJS project?
No. OpenJS encourages organizations to move to currently supported versions. Commercial support is the legacy-version option for organizations that cannot move immediately.
Is HeroDevs’ 15% revenue share still guaranteed?
The 15% figure was stated in OpenJS’s May 21, 2024 launch announcement. The maintained guidance lists HeroDevs as the current partner but does not independently repeat that percentage, so current terms must be confirmed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




