Empirically identifies downstream adoption delay as the primary driver of vulnerability persistence and validates package-level signals for predicting maintenance responsiveness.
Analysis of over 450 vulnerabilities and 200,000 infected npm packages reveals that while maintainers release security fixes in an average of 1.17 days, it takes downstream dependents an average of 6 months to adopt them. Up to 40% of npm packages depend on code with publicly disclosed vulnerabilities, and a single dependency declaration can implicitly expose a project to 79 upstream packages. The research found that dependents relying only on patch-level updates miss out on 30% of available vulnerability fixes, which are often bundled in minor or major releases. A predictive model (ROC-AUC 0.85) identifies package age, release frequency, and non-restrictive update strategies (e.g., using caret ^ instead of tilde ~) as the most reliable indicators of how quickly a package will adopt and propagate a security fix.
The study finds an average 6-month delay for downstream dependents to adopt vulnerability fixes that were released by upstream maintainers within 24 hours.
persistent exposure to known, patched vulnerabilities due to maintenance inertia
measuring the delta between fix release and adoption is the definitive indicator of whether a project's dependency management practices are responsive to security threats.
By relying only on patch updates, dependents miss out on 30% (on average) of vulnerability fixes... fixes are released in minor and major release types.
Risk Guard evaluates current versions but doesn't explicitly flag 'NPF' (No Patch Found) scenarios where a fix exists in a higher major version but not in the user's current version stream.
Risk Guard would be better if it performed 'Version Stream Gap Analysis' to alert when a vulnerability fix is only available by jumping to a higher major version.