Provides large-scale empirical validation of maintainer concentration and legacy version persistence, while documenting the accelerating industry adoption of memory-safe languages.
The Census III study, analyzing 12 million observations of FOSS libraries across 10,000 companies, identifies maintainer concentration and 'legacy drag' as primary supply chain risks. Research confirms the 'myth of many eyes': in 81% of top projects, 10 or fewer developers author 80% of commits, and 17% depend on just one primary contributor. Furthermore, backward incompatibility continues to trap organizations in insecure environments: Python 2 remains in use by 7% of all developers (rising to 29% in data analysis and 23% in DevOps) over a decade after its EOL. A significant positive trend is the 500% increase in Rust adoption since 2020, signaling a systemic industry shift toward memory-safe languages. The report strongly advocates for standardized naming schemas like PURL (Package URL) to resolve the persistent ambiguity of identical package names across different registries.
81% of critical projects rely on 10 or fewer developers for 80% of their code across their entire history, highlighting a systemic lack of contributor diversity.
dependency on critical libraries that have no institutional redundancy or peer-review capacity
historical author concentration is the primary driver of 'silent' abandonment risk, where a project appears active but has never attracted sufficient contributor diversity.
23% to 29% of Python users in critical sectors like DevOps still rely on Python 2, which has been end-of-life and unpatched for years.
long-term exposure to known, unpatchable vulnerabilities in legacy environments
tracking unpatched vulnerabilities in EOL environments (like Python 2) is the only way to measure the 'Legacy Drag' risk identified in the Census report.
In 47 of the top 50 non-npm projects in 2023, 17% had one developer accounting for more than 80% of commits authored... 64% had four or fewer.
Risk Guard evaluates contributor count but doesn't calculate 'Author Concentration' (e.g., commit distribution) to detect when a project is functionally a single-maintainer project.
Risk Guard would be better if it calculated a 'Commit Concentration' metric to identify projects where a single individual authors the vast majority of the code.