1 in 7 Software Dependencies Has No Active Maintainer, Study Finds
An analysis of 8,943 software components found that 13.4%, or 1,202 packages, show signs of having no active maintainer. About 80% of these were flagged through inference — specifically, no release or repository activity in over four years — rather than through an explicit deprecation notice. The study covered 24 public repositories across five ecosystems including npm, PyPI, Maven, Gradle, and Go, with npm showing the highest share of unmaintained packages at 15.1%. Researchers argue the key concern is not whether a package is flawed, but whether a fix would ever arrive if a new vulnerability were discovered. The findings highlight a gap in standard security reporting, which typically assumes an active maintainer exists to issue patches.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in