Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsCensus II is a 2022 study of free and open-source software (FOSS) application libraries observed in production applications—not a definitive or current ranking of the most important open-source projects. The Linux Foundation and the Laboratory for Innovation Science at Harvard (LISH), with support from the Open Source Security Foundation (OpenSSF), released the report on March 2, 2022. It used anonymized software-composition-analysis data to examine how companies used application libraries and to highlight issues affecting software supply-chain health.
What Census II studied
Census II followed the first Linux Foundation Census, which focused on lower-level operating-system libraries and utilities. The second study shifted to the application-library layer: packages incorporated into applications, including through dependencies. Its goal was to identify FOSS libraries widely deployed in production and help focus attention on software security and health. The report was authored by Frank Nagle, James Dana, Jennifer Hoffman, Steven Randazzo, and Yanuo Zhou. Read the Census II report.
The Linux Foundation’s release described a set of more than 1,000 widely deployed application libraries. The report’s appendices present eight separate Top 500 lists, each reflecting a different slice of the data rather than a single all-purpose ranking. The March 2, 2022 announcement also summarizes the study’s purpose and headline findings.
Where the data came from—and what the lists mean
The study combined more than half a million observations of FOSS libraries used in production applications at thousands of companies. The anonymized data came from software composition analysis (SCA) scans supplied by Snyk, Synopsys Cybersecurity Research Center (CyRC), and FOSSA. SCA tools inventory software components in codebases; here, their data provided a view into use in private production environments that is not generally visible from public repositories alone.
#1 Best Overall
Census II separated packages along three axes. To interpret or compare a list, match all three:
- Ecosystem: npm or non-npm. npm was separated because it was heavily represented and could dominate a combined list.
- Dependency relationship: direct dependencies called by the application, or direct plus indirect dependencies brought in through another package.
- Version handling: version-agnostic package names, or entries retaining version numbers.
For example, the release announcement’s top ten version-agnostic npm packages called directly in applications were, in order: lodash, react, axios, debug, @babel/core, express, semver, uuid, react-dom, and jquery. That is a result for one specific slice of the partner data—not a statement about today’s package popularity, the most critical projects, or all FOSS use.
Five issues the study brought into focus
Inconsistent component naming
Data providers used different names and conventions for software components, making records harder to reconcile. The authors argued that standardized identification would improve communication and supply-chain transparency. For organizations maintaining inventories or bills of materials, inconsistent identifiers can make it difficult to tell whether records refer to the same component.
Version information is complicated
Package-version data did not always align consistently between records and public repositories. The release announcement recommended that SBOM guidance align version information with a package’s public main repository rather than private repositories. This is the report’s recommendation; it should not be read as a description of every current SBOM standard.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- Used Book in Good Condition
Contributor activity can be concentrated
In one dataset, 136 developers were responsible for more than 80% of the lines of code added to the top 50 packages. This finding is limited to that dataset; it does not establish the same pattern across all projects or contributors, and contributor count alone does not measure project health. The report’s practical implication is that organizations relying on a package may have reason to support its maintainers.
Maintainer account security matters
A maintainer’s individual developer account can be a consequential point of control: if compromised, it may affect software distributed downstream. Census II highlighted developer-account security as an increasing concern in the open-source supply chain.
Legacy components remain in use
Old or infrequently updated components can persist in application dependencies. The report suggested that such projects may need revitalization—or that users may need help moving to newer alternatives. Their presence in a dependency inventory is a reason to investigate maintenance and transition options, not by itself proof of a vulnerability.
How to use Census II without overreading it
The report itself says its findings are indicative, not a definitive claim about which FOSS packages are most critical. The sample was limited to the SCA partners’ customer bases; privacy restrictions also prevented sufficiently specific data for representative sampling. In addition, some dependency calculations depended on package-identification information from Libraries.io or GitHub, so packages absent from those sources could be omitted or ranked lower.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBest Value
In practical terms, the lists measure observed use within the study’s scope. They do not measure each package’s vulnerability level, its importance to critical infrastructure, or the risk of relying on it. They can help direct questions—such as which dependencies deserve an inventory or maintenance review—but they are not a standalone risk score or a sufficient basis for funding and policy decisions.
The report also included an OpenSSF Best Practices badge “Tiered %” measure alongside package lists. It indicates progress against practices: 100% or above corresponds to passing, 200% or above to silver, and 300% or above to gold. It is not a vulnerability score.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Is Census II still current?
No: Census II is a historical 2022 snapshot. The Linux Foundation lists a later application-library study, Census III, which used data from FOSSA, Snyk, Sonatype, and Black Duck. The existence of that successor does not establish which individual packages are most used today; a current ranking requires the successor report’s own dated data and methods. See the Linux Foundation’s Census III page.
When comparing Census II with another list or study, check its study period, participating data providers, package-identification method, and represented population as well as whether the lists use the same ecosystem, dependency relationship, and version treatment. Otherwise, apparent rank changes may reflect different coverage or definitions rather than a real change in usage.
Why the findings matter
Census II’s value is less a timeless leaderboard than a structured look at issues that make open-source supply chains harder to understand and sustain: identifying components consistently, recording versions reliably, protecting maintainer accounts, and supporting projects whose use may exceed the visible contributor base. Brian Behlendorf, then executive director of OpenSSF, said in the March 2, 2022 release announcement that understanding widely used packages lets the community engage projects that warrant operations and security support. That rationale is useful, provided the report’s sample and scope remain attached to any conclusion drawn from its rankings.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

