deprecationnpmlegacyincumbent

request npm — Deprecation Issue

Provides a case study of a 'super-critical' package entering formal deprecation while maintaining a massive, unmanaged legacy dependency footprint.

Summary

The `request` module, one of the first ever added to the npm registry in 2009, formally entered permanent maintenance mode in 2020. At the time of its deprecation, the library was a critical ecosystem incumbent, with over 41,000 dependent modules (including the npm CLI) and 14 million weekly downloads. The maintainer argued that the project's dominance had become a liability, as its ubiquitous presence in tutorials and legacy stacks stifled the adoption of modern, faster alternatives. The transition to maintenance mode means that the project, despite its massive scale, will no longer consider new features or major releases, serving as a landmark case of a 'super-critical' project reaching structural obsolescence.

Related Checks

SOURCE_REPO_ABANDONED

The maintainer formally announced that the project will stop considering new features or major releases and enter permanent maintenance mode.

Adverse Outcome

reliance on a critical network component that is no longer evolving and may become incompatible with future Node.js versions

Because

formal maintenance-mode announcements are the ultimate signal of a project's future decay, regardless of its current popularity.

Gaps Analysis

Evidence

Request remains one of the most depended on modules in the registry... downloaded 14 million times a week. 41K modules depend on request.

Blind Spot

Risk Guard flags deprecated packages but does not provide a 'Migration Path' or 'Successor' recommendation for common legacy incumbents.

Actionable Capability

Risk Guard would be better if it suggested specifically vetted 'Successor' packages for formally deprecated incumbents like request.

← Previous Next →