censusresearchmaintainer-concentrationbackward-compatibilitymemory-safety

Linux Foundation / Harvard — Census III

Provides large-scale empirical validation of maintainer concentration and legacy version persistence, while documenting the accelerating industry adoption of memory-safe languages.

Summary

The Census III study, analyzing 12 million observations of FOSS libraries across 10,000 companies, identifies maintainer concentration and 'legacy drag' as primary supply chain risks. Research confirms the 'myth of many eyes': in 81% of top projects, 10 or fewer developers author 80% of commits, and 17% depend on just one primary contributor. Furthermore, backward incompatibility continues to trap organizations in insecure environments: Python 2 remains in use by 7% of all developers (rising to 29% in data analysis and 23% in DevOps) over a decade after its EOL. A significant positive trend is the 500% increase in Rust adoption since 2020, signaling a systemic industry shift toward memory-safe languages. The report strongly advocates for standardized naming schemas like PURL (Package URL) to resolve the persistent ambiguity of identical package names across different registries.

Related Checks

SOURCE_FEW_CONTRIBUTORS

81% of critical projects rely on 10 or fewer developers for 80% of their code across their entire history, highlighting a systemic lack of contributor diversity.

Adverse Outcome

dependency on critical libraries that have no institutional redundancy or peer-review capacity

Because

historical author concentration is the primary driver of 'silent' abandonment risk, where a project appears active but has never attracted sufficient contributor diversity.

VULN_UNFIXED

23% to 29% of Python users in critical sectors like DevOps still rely on Python 2, which has been end-of-life and unpatched for years.

Adverse Outcome

long-term exposure to known, unpatchable vulnerabilities in legacy environments

Because

tracking unpatched vulnerabilities in EOL environments (like Python 2) is the only way to measure the 'Legacy Drag' risk identified in the Census report.

Gaps Analysis

Evidence

In 47 of the top 50 non-npm projects in 2023, 17% had one developer accounting for more than 80% of commits authored... 64% had four or fewer.

Blind Spot

Risk Guard evaluates contributor count but doesn't calculate 'Author Concentration' (e.g., commit distribution) to detect when a project is functionally a single-maintainer project.

Actionable Capability

Risk Guard would be better if it calculated a 'Commit Concentration' metric to identify projects where a single individual authors the vast majority of the code.

← Previous Next →