Observed Signal · Apr 16, 2026 · Technical Release · Source: DEV Community · Impact: 3/5 · Sentiment: Positive
48% of Dependencies Are Unmaintained — SCA Tools Miss It
Kota Kanbe presented research at VulnCon 2026 showing that conventional SCA/vulnerability scanners (Trivy, Snyk, Grype) miss a large class of risk: unmaintained packages. Analysis of ~16,000 packages across ~100 organizations (published in Nikkei, March 2026) found 48.5% of production dependencies exhibit lifecycle risk (40.6% Active, 10.9% Legacy-Safe, 34.6% Stalled, 13.9% EOL). Kanbe released uzomuzo, an open-source tool (Apache 2.0) that classifies package lifecycle in seven stages using signals from deps.dev, the GitHub API and registry heuristics, evaluates build integrity, prioritizes removals, and integrates with CI. He demonstrates scanning (e.g., HashiCorp Vault: 209 deps, 11 EOL) and uses an LLM to trace data flow and produce attack scenarios. uzomuzo provides commands for scanning, prioritizing removal, and CI gating.
Reveals a sizable, under-detected software supply‑chain risk (48.5% lifecycle risk) and provides an automated, CI‑integratable tool that moves beyond CVE-based SCA — relevant to any org that depends on third‑party libraries, including AdTech platforms.
Track Nikkei Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Analysis covered ~16,000 packages across ~100 organizations; results published in Nikkei (March 2026).
- 48.5% of production dependencies were classified as having lifecycle risk (stalled or EOL).
- uzomuzo is an open-source tool (github.com/future-architect/uzomuzo-oss) released under Apache 2.0 that detects unmaintained packages SCA tools miss.
- uzomuzo uses seven lifecycle stages and multiple signal sources (deps.dev, GitHub API, registry heuristics) and evaluates lifecycle × build integrity.
- Example: scanning HashiCorp Vault (209 dependencies) found 11 EOL-confirmed packages with few or no CVEs.
Connected Companies & Entities
4 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Anthropic SDK Safe—but Two Transitive Deps Are Risky
A supply‑chain audit of the @anthropic-ai/sdk package shows the SDK itself scores healthy, but two transitive runtime dependencies present critical risks. json-schema-to-ts is a runtime dependency with a single maintainer and ~15M weekly downloads; its child dependency ts-algebra also has a sole maintainer and no release in 12+ months. The article argues standard tools like npm audit miss behavioral risk signals (single maintainer, high-download, low-maintenance) and demonstrates a depth‑2 dependency scan using the open-source Commit supply chain scanner (getcommit.dev/audit). The author recommends visibility (pinning versions, monitoring activity) rather than immediate removal and provides scan examples and curl/MCP usage for mapping dependency‑tree risk to depth 2.
Seven Open-Source DevSecOps Tools Developers Should Use
A Dev.to guide (Apr 25, 2026) recommends seven open-source security tools that are lightweight to integrate into CI/CD and catch practical vulnerabilities before deployment. The list covers Trivy (Aqua Security) for container, repo and IaC scanning with SARIF output for GitHub Security; Gitleaks for pre-commit and CI secret scanning; Semgrep for source-level static analysis and community rule registries; pompelmi as a minimal Node.js wrapper around ClamAV for file-upload scanning; OSV-Scanner (Google) for dependency vulnerability checks against the OSV database; OWASP ZAP for automated DAST; and Falco (CNCF) for eBPF-based runtime detection in Kubernetes. The author emphasizes shift-left automation, zero-friction tooling, defense-in-depth, and developer ownership of security.
Scan Finds Critical Vulnerabilities in 402 MCP npm Packages
A security researcher audited 2,386 Model Context Protocol (MCP) packages on the npm registry using a static-analysis scanner and an open detection standard called ATR (Agent Threat Rules). The scan extracted 35,858 tool definitions and found security findings in 49% of packages: 402 rated CRITICAL and 240 HIGH. Issues included SSH key exfiltration, hidden prompt injection, delayed backdoors, environment-variable credential harvesting, and over‑privileged tools that auto-execute on install. The author published ATR (61 rules, 474 detection patterns) and the PanGuard scanner as MIT-licensed open source, reporting 99.4% precision and 39.9% recall for detections. Responsible disclosure was carried out for high-risk packages. The results highlight supply-chain and agent-threat risks for AI agent ecosystems that install MCP packages with broad system access.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
