// open source · malmö, sweden
Over a decade working in the open
We upstream fixes, contribute features and help you pick the projects worth betting on, so that when something breaks deep in the stack, nobody has to wait for a vendor.
// what we do
Open source as a strategy, not just a licence
Choosing an open project is easy. Operating it, upgrading it and influencing where it goes is the part that decides whether the bet pays off.
Technology selection
Which projects are worth betting on? We look at governance, release cadence, maintainer diversity and issue hygiene, not GitHub stars.
Upstream contributions
When something is broken deep in the stack we read the code, fix it and get the patch merged upstream, so you stop carrying a private fork.
Fork and patch strategy
Sometimes a fork is the right call. We make it maintainable: minimal diffs, automated rebases and a plan to upstream the delta.
Supply-chain security
SBOMs, provenance with Sigstore, dependency scanning and a realistic policy for what you actually do when a CVE lands on a Friday.
Releasing your own project
Licensing, contribution guidelines, CI, release automation and community expectations, so opening a repository helps you instead of creating a support desk.
// lifecycle
How we treat a dependency
- 01→EvaluateHealth, governance and fit against your actual constraints.
- 02→AdoptPilot in a real workload with an exit plan written down.
- 03→OperateUpgrade cadence, alerting and ownership inside your team.
- 04→ContributeReport, patch and upstream, reducing your private diff.
- 05SustainTrack project health so a fading dependency is spotted early.
// ecosystem
Projects we know from the inside
// how to judge a project
Signals we look at before recommending anything
Maintainer diversity. A project run by a single company can change licence overnight. Several independent maintainers is a much stronger guarantee than any roadmap slide.
Release discipline. Predictable releases, clear deprecation policy and honest changelogs tell you more about long-term cost than feature count.
Issue hygiene. How maintainers respond to an awkward bug report is the best available preview of what your support experience will look like.
// faq
Common questions
Why does upstreaming matter to us as a customer?
Because a private patch is a permanent tax: every upgrade costs more. Getting the fix merged upstream removes that tax and often improves the project for everyone else too.
Can you help us decide between an open source tool and a SaaS product?
Yes, and the honest answer is often the SaaS. We weigh total cost including the engineering time to operate it: self-hosting is only cheaper when you have someone to run it.
Do you help with licence compliance?
We help with the practical parts: dependency inventory, licence classification and flagging combinations that need a lawyer's eye. We are engineers, not legal counsel.
// how we work
// contact
Depending on a project you cannot debug?
Tell us which part of the stack worries you and we will take a look.
office: Malmö, Sweden · uppdrag across Europe