Published September 11, 2026 ยท Added September 22, 2026

Nobody left to fix it: measuring how many dependencies have no maintainer

Dependency-scanning vendor depproof analyzed 24 repositories covering 8,943 components and found about one in seven (1,202 components, or 13.4%) carried a signal that no one is maintaining it. Roughly four in five of those signals were inferred from silence, meaning four years without a release and no repository activity, while the rest came from explicit deprecation flags, archived repositories, or published end-of-support dates; the company argues teams should track abandoned-dependency risk separately from known vulnerabilities because scanners rarely flag who is still around to publish a fix.

Dependency-scanning vendor depproof analyzed 24 repositories covering 8,943 components and found about one in seven (1,202 components, or 13.4%) carried a signal that no one is maintaining it. Roughly four in five of those signals were inferred from silence, meaning four years without a release and no repository activity, while the rest came from explicit deprecation flags, archived repositories, or published end-of-support dates; the company argues teams should track abandoned-dependency risk separately from known vulnerabilities because scanners rarely flag who is still around to publish a fix.

Read the original story.

Source: Depproof