OSS Maintainers & Foundations
Decisions about roadmap, deprecation, and funding currently rely on
downloads and intuition.
- Evidence for funding applications
- Roadmap prioritization based on actual usage
- Sunset decisions with data backing
- Without building your own data pipeline
Software Vendors
Supply chain risk today is a list of package names, not a reliable
assessment.
- Dependency health snapshots
- Supply chain early warning
- Industry benchmarking
- All from Open Data, no contract required
Research & Public
Each study currently starts with its own data procurement — not
reproducible, not comparable.
- Daily dump as Parquet and CSV.gz
- Reproducible data backbone
- Public audit log for verification
- CC-BY-4.0, with Provisional clause until legal clearance
Security Community
Whether an unmaintained library is dangerous depends on how widely it is
actually used.
- Prospective reach view on unmaintained libraries
- Correlation with CVE databases
- Prioritization based on actual usage
- Re-identification demos explicitly welcome