Quantifies the 'Supercoder' concentration risk and the 'Legacy Persistence' paradox where EOL components like Log4j 1.x continue to dominate production environments.
The Census II study, analyzing 500,000 FOSS usage observations, found that 70-90% of modern software is composed of open-source libraries. Research identified a high concentration of risk among 'supercoders': in the top 50 FOSS projects, a tiny group of 136 developers authored more than 80% of all code. The study also documented a 'Legacy Persistence' crisis: Log4j 1.x (declared EOL in 2015) was found to be ten times more prevalent in production applications than the modern, fixed 2.x versions. Furthermore, the analysis revealed that many critical packages are hosted on personal developer accounts that lack basic security protections like multi-factor authentication (MFA), creating a systemic 'account takeover' risk for the global software supply chain.
A tiny group of 136 'supercoders' author 80% of the code for the world's most critical 50 projects across their entire history.
systemic collapse of global infrastructure due to the burnout or removal of a few hundred key individuals
historically low contributor diversity is the primary driver of systemic maintenance risk in the open source ecosystem.
Log4j 1.x (EOL in 2015) was found to be 10x more prevalent than modern versions, with no human commits for over a decade.
inclusion of legacy components that have been functionally abandoned with no prospect of future maintenance
Log4j 1.x's decade of inactivity well exceeds the abandonment threshold, representing the 'Legacy Persistence' crisis where EOL code dominates production environments.
136 developers were responsible for more than 80% of the lines of code added to the top 50 packages... many were hosted on individual (personal) developer accounts.
Risk Guard evaluates repository health but does not explicitly distinguish between 'Organizational' and 'Personal' account hosting for critical dependencies.
Risk Guard would be better if it flagged dependencies hosted on personal accounts as a higher risk factor for account-takeover and abandonment compared to organizational ones.