Observed Signal · Apr 16, 2026 · Technical Release · Source: DEV Community · Impact: 3/5 · Sentiment: Positive

48% of Dependencies Are Unmaintained — SCA Tools Miss It

Executive Signal Summary

Kota Kanbe presented research at VulnCon 2026 showing that conventional SCA/vulnerability scanners (Trivy, Snyk, Grype) miss a large class of risk: unmaintained packages. Analysis of ~16,000 packages across ~100 organizations (published in Nikkei, March 2026) found 48.5% of production dependencies exhibit lifecycle risk (40.6% Active, 10.9% Legacy-Safe, 34.6% Stalled, 13.9% EOL). Kanbe released uzomuzo, an open-source tool (Apache 2.0) that classifies package lifecycle in seven stages using signals from deps.dev, the GitHub API and registry heuristics, evaluates build integrity, prioritizes removals, and integrates with CI. He demonstrates scanning (e.g., HashiCorp Vault: 209 deps, 11 EOL) and uses an LLM to trace data flow and produce attack scenarios. uzomuzo provides commands for scanning, prioritizing removal, and CI gating.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Reveals a sizable, under-detected software supply‑chain risk (48.5% lifecycle risk) and provides an automated, CI‑integratable tool that moves beyond CVE-based SCA — relevant to any org that depends on third‑party libraries, including AdTech platforms.

SIGNAL RADAR

Track Nikkei Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Analysis covered ~16,000 packages across ~100 organizations; results published in Nikkei (March 2026).
  • 48.5% of production dependencies were classified as having lifecycle risk (stalled or EOL).
  • uzomuzo is an open-source tool (github.com/future-architect/uzomuzo-oss) released under Apache 2.0 that detects unmaintained packages SCA tools miss.
  • uzomuzo uses seven lifecycle stages and multiple signal sources (deps.dev, GitHub API, registry heuristics) and evaluates lifecycle × build integrity.
  • Example: scanning HashiCorp Vault (209 dependencies) found 11 EOL-confirmed packages with few or no CVEs.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Apr 16, 2026
Original Coverage Title: “Your dependencies are 48% unmaintained — and SCA tools can't see it”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Software Supply Chain SecurityApr 26, 2026

Anthropic SDK Safe—but Two Transitive Deps Are Risky

A supply‑chain audit of the @anthropic-ai/sdk package shows the SDK itself scores healthy, but two transitive runtime dependencies present critical risks. json-schema-to-ts is a runtime dependency with a single maintainer and ~15M weekly downloads; its child dependency ts-algebra also has a sole maintainer and no release in 12+ months. The article argues standard tools like npm audit miss behavioral risk signals (single maintainer, high-download, low-maintenance) and demonstrates a depth‑2 dependency scan using the open-source Commit supply chain scanner (getcommit.dev/audit). The author recommends visibility (pinning versions, monitoring activity) rather than immediate removal and provides scan examples and curl/MCP usage for mapping dependency‑tree risk to depth 2.

Read assessment
Developer Security / DevSecOpsApr 25, 2026

Seven Open-Source DevSecOps Tools Developers Should Use

A Dev.to guide (Apr 25, 2026) recommends seven open-source security tools that are lightweight to integrate into CI/CD and catch practical vulnerabilities before deployment. The list covers Trivy (Aqua Security) for container, repo and IaC scanning with SARIF output for GitHub Security; Gitleaks for pre-commit and CI secret scanning; Semgrep for source-level static analysis and community rule registries; pompelmi as a minimal Node.js wrapper around ClamAV for file-upload scanning; OSV-Scanner (Google) for dependency vulnerability checks against the OSV database; OWASP ZAP for automated DAST; and Falco (CNCF) for eBPF-based runtime detection in Kubernetes. The author emphasizes shift-left automation, zero-friction tooling, defense-in-depth, and developer ownership of security.

Read assessment
Large Language Models (LLM) & AIMar 22, 2026

Scan Finds Critical Vulnerabilities in 402 MCP npm Packages

A security researcher audited 2,386 Model Context Protocol (MCP) packages on the npm registry using a static-analysis scanner and an open detection standard called ATR (Agent Threat Rules). The scan extracted 35,858 tool definitions and found security findings in 49% of packages: 402 rated CRITICAL and 240 HIGH. Issues included SSH key exfiltration, hidden prompt injection, delayed backdoors, environment-variable credential harvesting, and over‑privileged tools that auto-execute on install. The author published ATR (61 rules, 474 detection patterns) and the PanGuard scanner as MIT-licensed open source, reporting 99.4% precision and 39.9% recall for detections. Responsible disclosure was carried out for high-risk packages. The results highlight supply-chain and agent-threat risks for AI agent ecosystems that install MCP packages with broad system access.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.