Empirically validates that mature foundational codebases are statistically safer than new code, while documenting the long 'median lifetime' of supply chain vulnerabilities.
A 7.5-year study of the OpenBSD operating system confirms that software security statistically improves with age—software is 'like wine, not milk.' Research found that 61% of the source code is foundational (unchanged for over 7 years), and the rate of reporting foundational vulnerabilities decreased from 0.051 to 0.024 per day during the study. However, this 'purification' process is exceedingly slow: foundational vulnerabilities were found to have a median lifetime of at least 2.6 years (961 days). The vulnerability density for foundational code averaged 0.006 per thousand lines of code, significantly lower than the industry standard defect density (3-6 per KLOC), suggesting that mature codebases eventually reach a high level of security stability despite the persistence of long-latent flaws.
The study shows that foundational (older) code is significantly safer, as many vulnerabilities have already been discovered and removed over its long lifetime.
high exposure to 'infant' vulnerabilities in unvetted, newly introduced codebases
newer code lacks the multi-year 'purification' period that foundational code undergoes, making it a statistically higher risk for undiscovered flaws.
Foundational vulnerabilities have a median lifetime of at least 2.6 years (961 days)... 61% of lines of code are foundational.
Risk Guard does not explicitly weight 'Foundational Code' (unchanged for 2+ years) as inherently safer or 'lower risk' than newly introduced code.
Risk Guard would be better if it applied a 'Code Maturity' discount to risk scores for packages that are composed predominantly of long-standing, purified foundational code.