censusresearchmaintainer-concentrationlegacy-versionaccount-security

Linux Foundation / Harvard — Census II

Quantifies the 'Supercoder' concentration risk and the 'Legacy Persistence' paradox where EOL components like Log4j 1.x continue to dominate production environments.

Summary

The Census II study, analyzing 500,000 FOSS usage observations, found that 70-90% of modern software is composed of open-source libraries. Research identified a high concentration of risk among 'supercoders': in the top 50 FOSS projects, a tiny group of 136 developers authored more than 80% of all code. The study also documented a 'Legacy Persistence' crisis: Log4j 1.x (declared EOL in 2015) was found to be ten times more prevalent in production applications than the modern, fixed 2.x versions. Furthermore, the analysis revealed that many critical packages are hosted on personal developer accounts that lack basic security protections like multi-factor authentication (MFA), creating a systemic 'account takeover' risk for the global software supply chain.

Related Checks

SOURCE_FEW_CONTRIBUTORS

A tiny group of 136 'supercoders' author 80% of the code for the world's most critical 50 projects across their entire history.

Adverse Outcome

systemic collapse of global infrastructure due to the burnout or removal of a few hundred key individuals

Because

historically low contributor diversity is the primary driver of systemic maintenance risk in the open source ecosystem.

SOURCE_REPO_ABANDONED

Log4j 1.x (EOL in 2015) was found to be 10x more prevalent than modern versions, with no human commits for over a decade.

Adverse Outcome

inclusion of legacy components that have been functionally abandoned with no prospect of future maintenance

Because

Log4j 1.x's decade of inactivity well exceeds the abandonment threshold, representing the 'Legacy Persistence' crisis where EOL code dominates production environments.

Gaps Analysis

Evidence

136 developers were responsible for more than 80% of the lines of code added to the top 50 packages... many were hosted on individual (personal) developer accounts.

Blind Spot

Risk Guard evaluates repository health but does not explicitly distinguish between 'Organizational' and 'Personal' account hosting for critical dependencies.

Actionable Capability

Risk Guard would be better if it flagged dependencies hosted on personal accounts as a higher risk factor for account-takeover and abandonment compared to organizational ones.

← Previous Next →