Shipyard announced it is winding down IPFS work:
Protocol Labs declined to renew the funding, and the projects Shipyard maintained will have no dedicated maintainers after September 30. So what happened to the independence announced in 2023? If a single funder’s decision can end all maintenance, the Foundation looks like an accounting arrangement, not independence.
I run IPFS Kubo and Helia nodes and build on this stack, so before the team disperses I would like to understand a few practical things:
- Security: who triages vulnerability reports and ships fixes for Kubo, Boxo and Helia after September? Will the disclosure contact listed in community/SECURITY.md at master · ipfs/community · GitHub still reach anyone?
- Releases: will anyone cut releases at all, or should operators pin current versions and plan around that? Should we expect a community fork?
- Infrastructure: the post says Protocol Labs retains
ipfs.io,dweb.linkanddelegated-ipfs.dev. Who operates them day to day after September, and what experience do they have running public infrastructure at this scale? - What happens to the Service Worker Gateway at https://inbrowser.link?
- What happens to Badbits at https://badbits.dwebops.pub? Does it break when Shipyard turns the lights off?
- Direction: when NFT.Storage, Web3.Storage and then Storacha wound down its IPFS service this spring, users were pointed at Fil One (https://www.fil.one/), a paid AWS S3-compatible product. Is something similar planned for the public gateways, or will they stay a neutral public service?
None of this is a knock on the Shipyard folks, who kept these projects alive for years and are offering transition help through the end of September. The community got better notice than when Storacha or Fleek shut down abruptly.
I just want to understand what’s next. Be honest with us: if the plan is to pretend these projects are maintained with LLMs, say so now, so we can plan migration away from IPFS.