Open-source software is embedded across production applications, and the Linux Foundation’s Census III finds that this usage is shifting across package ecosystems while leaving persistent risks around vulnerable components, thin maintainer teams and developer-account security. The study, published December 4, 2024, offers organizations a way to think about which dependencies merit attention—not a guarantee that every widely used package is secure or unsafe.
What Census III measured
Census III of Free and Open Source Software – Application Libraries was produced by the Linux Foundation and the Laboratory for Innovation Science at Harvard. It aggregates anonymized usage data from software composition analysis (SCA) partners Black Duck, FOSSA, Snyk and Sonatype. The dataset contains more than 12 million observations of FOSS libraries in production applications at more than ten thousand companies, according to the Linux Foundation and Harvard in 2024.
The findings describe observed library use in the partners’ data. They are useful for understanding patterns and prioritizing attention, but should not be read as a census of every organization, application or open-source project.
Which open-source usage trends stand out?
Cloud-specific packages are gaining use
The study identifies increasing use of packages tied to cloud services. As applications depend on more cloud-specific libraries, organizations need inventories that capture those dependencies as well as more familiar, general-purpose packages.
Recommended Free Tools
#1 Best Overall
Package ecosystems are changing at different rates
The report notes continuing migration from Python 2 to Python 3. Maven remains widely used, while NuGet and Python packages are increasingly prevalent. Rust repository components have also increased considerably since Census II. These are distinct shifts rather than one uniform move away from established ecosystems: Maven remains significant even as use of other package types grows.
Older components remain in the mix
Legacy software continues to appear in the open-source ecosystem. Its persistence can complicate patching and modernization, particularly when teams lack a reliable record of where older components are deployed.
Rank #2
What security challenges does the study highlight?
Dependency inventories need consistent names
Component naming is not a minor data-cleanup issue. The report calls for standardized naming schemas because organizations need to identify components consistently before they can build dependable dependency inventories or analyze security exposure. Inconsistent names can make it harder to tell whether records refer to the same library and to connect an alert to the software actually in use.
Popular software may depend on a small maintainer group
Some widely used FOSS is developed by only a handful of contributors. That concentration can create continuity risk: if a small team cannot maintain a project, fix issues or keep releases moving, downstream users may face delays or uncertainty. Usage alone does not reveal a project’s full health, so organizations should consider maintainer capacity alongside a component’s role in their applications.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Maintainer and publisher accounts are part of the supply chain
The study emphasizes individual developer-account security. A compromised maintainer or publisher account can affect downstream consumers who trust the account or its releases. Tim Mackey of Black Duck highlighted the business risk associated with a small contributor base or an effectively anonymous GitHub account. This makes account protection and clear publisher identity relevant to dependency risk management, not just to the security of an individual developer’s workstation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How organizations can apply the findings
Census III is intended to help organizations direct security and maintenance investment toward widely used components. A practical review can translate its findings into a repeatable process:
Rank #4
- Build and normalize an inventory. Use SCA and other inventory processes to identify dependencies across applications, and standardize component names so records can be matched and analyzed consistently.
- Prioritize components in context. Consider how widely a component is used inside the organization and how important the applications that depend on it are. The study’s usage patterns help frame attention, but do not by themselves establish that a component is vulnerable.
- Review maintenance and account signals. For important dependencies, examine whether development rests on a small contributor group and whether the publisher identity and account security are trustworthy.
- Plan for older dependencies. Identify legacy components in the inventory and determine how the organization will handle patching, upgrades or replacement when modernization is difficult.
- Keep ecosystem coverage current. Account for cloud-specific packages and the relevant language and repository ecosystems, including Python, Maven, NuGet and Rust, rather than assuming a dependency program focused on one package type is sufficient.
The report’s central point is that open-source health is a supply-chain concern. David A. Wheeler of OpenSSF described FOSS as “now ubiquitous, serving as a foundational infrastructure of society.” Hilary Carter, SVP Research at the Linux Foundation, said that understanding open-source health and security posture is critical to sustainability. For organizations, that means treating dependency visibility, maintenance capacity and publisher-account security as connected parts of managing software risk.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →

