Provides long-term trend data on the accelerating pace of open-source development and the corresponding breakdown in maintainer remediation capacity.
A 10-year retrospective of the software supply chain reveals a 1,466% increase in release frequency and 463% growth in CVEs between 2014-2023. More than 704,000 malicious packages have been discovered since 2019, doubling in volume in 2024 alone. Most critically, the mean time to remediate (MTTR) vulnerabilities has collapsed: while critical issues in 2017 were fixed in under 25 days, they now take an average of over 500 days in 2024. Despite 3x growth in SBOM publishing since 2022, adoption remains linear and far outpaced by the exponential growth of new components, leaving 95% of vulnerable downloads targeting versions that already have a fix available.
The MTTR for critical vulnerabilities has ballooned from under 25 days in 2017 to over 500 days in 2024, showing a total breakdown in maintenance capacity.
indefinite exposure to critical exploits due to a project's inability to maintain its dependency tree
the dramatic upward trend in MTTR is the single most important indicator of a project's long-term security viability.
Mean time to remediate vulnerabilities is slowing significantly... critical issues in 2024 took over 500 days to fix, indicating response times for severe issues are worsening.
Risk Guard uses current fix status but does not project 'Expected Time to Fix' based on a project's historical MTTR trends.
Risk Guard would be better if it provided an 'Estimated Remediation Window' for unpatched CVEs based on the maintainer's 3-year MTTR average.