Dormancy vs dependents

Commit counts for 2,676 open-source repositories, ranked by how many other repositories depend on them. Measured 6 September 2026.

The finding

The more projects depend on a repository, the less likely anyone committed to it this year. Sixty of the hundred most depended-upon repositories made no commit at all to their default branch between 1 January and 31 August 2026. Below rank 1,000 that figure is 41%.

Ranked by dependent repositoriesReposNo commits in 8 monthsMedian commits
Top 10010060 (60%)0
Top 250250147 (59%)0
Ranks 251–1,000750474 (63%)0
Ranks 1,001+1,676688 (41%)4

Take the data

dormancy-2026-09.csv — 2,676 rows, one per repository: repository, dependent_repos, commits_jan_aug_2026, days_measured. No sign-up, no email required.

Licence: CC BY-SA 4.0. The dependent_repos column is derived from ecosyste.ms, whose data is published under CC BY-SA 4.0, so this derivative carries the same licence and the same attribution requirement. Credit ecosyste.ms and Anteproof, and share any derivative alike. Commit counts are from the GitHub REST API.

How it was measured

What this does not mean

Dormant is not abandoned. A small utility that does one thing correctly may simply be finished. Zero commits can mean stability.

Dependent counts are transitive. Five and a half million repositories did not each choose fs.realpath; they inherited it through a lockfile. Nobody should use this file to shame a maintainer.

Why we published it

From 11 September 2026 the EU Cyber Resilience Act requires a manufacturer to report an actively exploited vulnerability within 24 hours. A bill of materials tells you what is in the product; it does not tell you whether anyone is still home to fix it. That is the question Anteproof forecasts, and the record, including the families we are currently withholding and why, is on the calibration page.

A probability is not advice, and we never call a package safe.