Published in News

Open-source projects are not properly maintained

by on16 October 2023


Just 11 per cent are viable

A recent analysis of 1.2 million open source software projects primarily across four ecosystems found that only about 11 per cent of projects were actively maintained.

In its Ninth Annual State of the Software Supply Chain report software supply chain management company Sonatype assessed 1,176,407 projects and reported an 18 per cent decline this year in actively maintained projects. Just 11 per cent of projects — 118,028 — were receiving active maintenance.

The report also found some new projects, unmaintained in 2022, now being maintained.

The four ecosystems included JavaScript via NPM; Java, via the Maven project management tool; Python, via the PyPI package index; and .NET, through the NuGet gallery. Some Go projects were also included. According to the report, 18.6 per cent of Java and JavaScript projects maintained in 2022 are no longer being maintained.

Nearly 10 per cent reported security breaches due to open-source vulnerabilities in the past 12 months.

 

Last modified on 16 October 2023
Rate this item
(2 votes)