Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Open-source software is embedded across production applications, and the Linux Foundation’s Census III finds that this usage is shifting across package ecosystems while leaving persistent risks around vulnerable components, thin maintainer teams and developer-account security. The study, published December 4, 2024, offers organizations a way to think about which dependencies merit attention—not a guarantee that every widely used package is secure or unsafe.

What Census III measured

Census III of Free and Open Source Software – Application Libraries was produced by the Linux Foundation and the Laboratory for Innovation Science at Harvard. It aggregates anonymized usage data from software composition analysis (SCA) partners Black Duck, FOSSA, Snyk and Sonatype. The dataset contains more than 12 million observations of FOSS libraries in production applications at more than ten thousand companies, according to the Linux Foundation and Harvard in 2024.

The findings describe observed library use in the partners’ data. They are useful for understanding patterns and prioritizing attention, but should not be read as a census of every organization, application or open-source project.

Which open-source usage trends stand out?

Cloud-specific packages are gaining use

The study identifies increasing use of packages tied to cloud services. As applications depend on more cloud-specific libraries, organizations need inventories that capture those dependencies as well as more familiar, general-purpose packages.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Package ecosystems are changing at different rates

The report notes continuing migration from Python 2 to Python 3. Maven remains widely used, while NuGet and Python packages are increasingly prevalent. Rust repository components have also increased considerably since Census II. These are distinct shifts rather than one uniform move away from established ecosystems: Maven remains significant even as use of other package types grows.

Older components remain in the mix

Legacy software continues to appear in the open-source ecosystem. Its persistence can complicate patching and modernization, particularly when teams lack a reliable record of where older components are deployed.

What security challenges does the study highlight?

Dependency inventories need consistent names

Component naming is not a minor data-cleanup issue. The report calls for standardized naming schemas because organizations need to identify components consistently before they can build dependable dependency inventories or analyze security exposure. Inconsistent names can make it harder to tell whether records refer to the same library and to connect an alert to the software actually in use.

Popular software may depend on a small maintainer group

Some widely used FOSS is developed by only a handful of contributors. That concentration can create continuity risk: if a small team cannot maintain a project, fix issues or keep releases moving, downstream users may face delays or uncertainty. Usage alone does not reveal a project’s full health, so organizations should consider maintainer capacity alongside a component’s role in their applications.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Maintainer and publisher accounts are part of the supply chain

The study emphasizes individual developer-account security. A compromised maintainer or publisher account can affect downstream consumers who trust the account or its releases. Tim Mackey of Black Duck highlighted the business risk associated with a small contributor base or an effectively anonymous GitHub account. This makes account protection and clear publisher identity relevant to dependency risk management, not just to the security of an individual developer’s workstation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How organizations can apply the findings

Census III is intended to help organizations direct security and maintenance investment toward widely used components. A practical review can translate its findings into a repeatable process:

  1. Build and normalize an inventory. Use SCA and other inventory processes to identify dependencies across applications, and standardize component names so records can be matched and analyzed consistently.
  2. Prioritize components in context. Consider how widely a component is used inside the organization and how important the applications that depend on it are. The study’s usage patterns help frame attention, but do not by themselves establish that a component is vulnerable.
  3. Review maintenance and account signals. For important dependencies, examine whether development rests on a small contributor group and whether the publisher identity and account security are trustworthy.
  4. Plan for older dependencies. Identify legacy components in the inventory and determine how the organization will handle patching, upgrades or replacement when modernization is difficult.
  5. Keep ecosystem coverage current. Account for cloud-specific packages and the relevant language and repository ecosystems, including Python, Maven, NuGet and Rust, rather than assuming a dependency program focused on one package type is sufficient.

The report’s central point is that open-source health is a supply-chain concern. David A. Wheeler of OpenSSF described FOSS as “now ubiquitous, serving as a foundational infrastructure of society.” Hilary Carter, SVP Research at the Linux Foundation, said that understanding open-source health and security posture is critical to sustainability. For organizations, that means treating dependency visibility, maintenance capacity and publisher-account security as connected parts of managing software risk.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.