Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Census II is a 2022 study of free and open-source software (FOSS) application libraries observed in production applications—not a definitive or current ranking of the most important open-source projects. The Linux Foundation and the Laboratory for Innovation Science at Harvard (LISH), with support from the Open Source Security Foundation (OpenSSF), released the report on March 2, 2022. It used anonymized software-composition-analysis data to examine how companies used application libraries and to highlight issues affecting software supply-chain health.

What Census II studied

Census II followed the first Linux Foundation Census, which focused on lower-level operating-system libraries and utilities. The second study shifted to the application-library layer: packages incorporated into applications, including through dependencies. Its goal was to identify FOSS libraries widely deployed in production and help focus attention on software security and health. The report was authored by Frank Nagle, James Dana, Jennifer Hoffman, Steven Randazzo, and Yanuo Zhou. Read the Census II report.

The Linux Foundation’s release described a set of more than 1,000 widely deployed application libraries. The report’s appendices present eight separate Top 500 lists, each reflecting a different slice of the data rather than a single all-purpose ranking. The March 2, 2022 announcement also summarizes the study’s purpose and headline findings.

Where the data came from—and what the lists mean

The study combined more than half a million observations of FOSS libraries used in production applications at thousands of companies. The anonymized data came from software composition analysis (SCA) scans supplied by Snyk, Synopsys Cybersecurity Research Center (CyRC), and FOSSA. SCA tools inventory software components in codebases; here, their data provided a view into use in private production environments that is not generally visible from public repositories alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Census II separated packages along three axes. To interpret or compare a list, match all three:

  • Ecosystem: npm or non-npm. npm was separated because it was heavily represented and could dominate a combined list.
  • Dependency relationship: direct dependencies called by the application, or direct plus indirect dependencies brought in through another package.
  • Version handling: version-agnostic package names, or entries retaining version numbers.

For example, the release announcement’s top ten version-agnostic npm packages called directly in applications were, in order: lodash, react, axios, debug, @babel/core, express, semver, uuid, react-dom, and jquery. That is a result for one specific slice of the partner data—not a statement about today’s package popularity, the most critical projects, or all FOSS use.

Five issues the study brought into focus

Inconsistent component naming

Data providers used different names and conventions for software components, making records harder to reconcile. The authors argued that standardized identification would improve communication and supply-chain transparency. For organizations maintaining inventories or bills of materials, inconsistent identifiers can make it difficult to tell whether records refer to the same component.

Version information is complicated

Package-version data did not always align consistently between records and public repositories. The release announcement recommended that SBOM guidance align version information with a package’s public main repository rather than private repositories. This is the report’s recommendation; it should not be read as a description of every current SBOM standard.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Contributor activity can be concentrated

In one dataset, 136 developers were responsible for more than 80% of the lines of code added to the top 50 packages. This finding is limited to that dataset; it does not establish the same pattern across all projects or contributors, and contributor count alone does not measure project health. The report’s practical implication is that organizations relying on a package may have reason to support its maintainers.

Maintainer account security matters

A maintainer’s individual developer account can be a consequential point of control: if compromised, it may affect software distributed downstream. Census II highlighted developer-account security as an increasing concern in the open-source supply chain.

Legacy components remain in use

Old or infrequently updated components can persist in application dependencies. The report suggested that such projects may need revitalization—or that users may need help moving to newer alternatives. Their presence in a dependency inventory is a reason to investigate maintenance and transition options, not by itself proof of a vulnerability.

How to use Census II without overreading it

The report itself says its findings are indicative, not a definitive claim about which FOSS packages are most critical. The sample was limited to the SCA partners’ customer bases; privacy restrictions also prevented sufficiently specific data for representative sampling. In addition, some dependency calculations depended on package-identification information from Libraries.io or GitHub, so packages absent from those sources could be omitted or ranked lower.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In practical terms, the lists measure observed use within the study’s scope. They do not measure each package’s vulnerability level, its importance to critical infrastructure, or the risk of relying on it. They can help direct questions—such as which dependencies deserve an inventory or maintenance review—but they are not a standalone risk score or a sufficient basis for funding and policy decisions.

The report also included an OpenSSF Best Practices badge “Tiered %” measure alongside package lists. It indicates progress against practices: 100% or above corresponds to passing, 200% or above to silver, and 300% or above to gold. It is not a vulnerability score.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is Census II still current?

No: Census II is a historical 2022 snapshot. The Linux Foundation lists a later application-library study, Census III, which used data from FOSSA, Snyk, Sonatype, and Black Duck. The existence of that successor does not establish which individual packages are most used today; a current ranking requires the successor report’s own dated data and methods. See the Linux Foundation’s Census III page.

When comparing Census II with another list or study, check its study period, participating data providers, package-identification method, and represented population as well as whether the lists use the same ecosystem, dependency relationship, and version treatment. Otherwise, apparent rank changes may reflect different coverage or definitions rather than a real change in usage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the findings matter

Census II’s value is less a timeless leaderboard than a structured look at issues that make open-source supply chains harder to understand and sustain: identifying components consistently, recording versions reliably, protecting maintainer accounts, and supporting projects whose use may exceed the visible contributor base. Brian Behlendorf, then executive director of OpenSSF, said in the March 2, 2022 release announcement that understanding widely used packages lets the community engage projects that warrant operations and security support. That rationale is useful, provided the report’s sample and scope remain attached to any conclusion drawn from its rankings.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.