Sighttrue
Last reading 2026-08-07 14:41 UTC age unavailable without scripting

What the readings actually say.

Every other page here is a table, which is the right shape for a reading and the wrong shape for a claim. These are the things worth saying out loud — each with the sample it rests on and a link to the numbers behind it.

Every sentence on this page is assembled from the published data with its figures filled in. None of it is written by hand or by a model, so none of it can drift from what was measured. A finding whose numbers fall below the bar it needs stops appearing.

Finding 1 of 9 See the readings

84 of 387 widely used projects rest half their history on one person

Counting from the most prolific contributor down, one person accounts for half of all commits. The most concentrated is ethers-io/ethers.js, where the largest single contributor wrote 100% of 826 commits.

What it rests on. Contributor histories of 387 repositories, read weekly from GitHub. Commit count is not contribution, and this is history rather than the present.

Why it is not published elsewhere. Every health signal in circulation measures activity. None measures who is producing it.

Finding 2 of 9 See the readings

22 of 158 tracked packages have not shipped a release in over a year

Read from the registries rather than from a repository’s last push — a push is what a maintainer does for themselves, a release is what reaches the projects depending on them. The longest silence is rails on npm, 4,649 days.

What it rests on. 158 packages across npm, PyPI and crates.io, read daily. Median time since release across all of them is 31 days.

Why it is not published elsewhere. Every "is this maintained" badge reads the wrong field.

Finding 3 of 9 See the readings

123 package names one keystroke from something you install already exist on npm

Generated by deleting or transposing one character in a real package name, then asked of the registry directly. bootstrap alone has 15: boostrap, boosttrap, bootsrap, bootsrtap.

What it rests on. 31 of the most installed packages swept. Deletions and transpositions only, so this finds fewer than exist. Existence is the entire claim — none of these is called malicious.

Why it is not published elsewhere. npm’s own search ranks by popularity, which is exactly the ordering that hides these.

Finding 4 of 9 See the readings

A pypi package carries 6.8× the advisory load of a crates one

Among packages with at least one advisory on record, pypi averages 59.5 and crates averages 8.7.

What it rests on. 3,941 all-time advisories across hand-picked prominent projects, from OSV. Counts are all-time, so age and scrutiny raise them as readily as danger, and the registries differ in size and age.

Why it is not published elsewhere. Advisory counts are published per package. Nobody totals them per ecosystem.

Finding 5 of 9 See the readings

Stack Overflow volume fell 24.2% for the median tag in 30 days

Across two equal windows. That fall is now the baseline rather than the finding, so what matters is the spread around it: typescript held up 31.9 points better than the median tag.

What it rests on. 30 tags, 534 questions in the recent window. A tag with under 25 questions in the earlier window gets no percentage at all.

Why it is not published elsewhere. The collapse is discussed everywhere and measured per tag almost nowhere.

Finding 6 of 9 See the readings

OpenAI announced 92 incidents in 90 days

Their own status feed, kept after it stopped carrying them. Atlassian announced none in the same window. A count measures how often a provider publishes, so one that discloses every degradation out-counts one that stays quiet.

What it rests on. 441 incidents across 20 providers, 714 days on record here. Never read a low number as a good one.

Why it is not published elsewhere. Every status page forgets after a few months. This one does not.

Finding 7 of 9 See the readings

Python is named in 20.8% of hiring posts

Counted across one month of Hacker News job posts. The largest move against last month is Python, up 5.8 points.

What it rests on. 284 posts in 2026-08, compared against 434 the month before. One forum, skewed hard toward American startups — evidence about that population and no wider one.

Why it is not published elsewhere. Every other signal here measures what developers publish. This measures what somebody paid to ask for.

Finding 8 of 9 See the readings

The heaviest base image tracked here is 7× the lightest

rust:1 is 597 MB against 83 MB for golang:1.24-alpine, on every pull, on every build.

What it rests on. 39 tags across 15 official images, read daily from Docker Hub with the date each was last rebuilt.

Why it is not published elsewhere. Sizes are published per tag. Nobody puts them beside each other.

Finding 9 of 9 See the readings

24 tracked release lines stop getting security fixes within a year

The soonest is rails 7.2, which ends on 2026-08-09 — 2 days away.

What it rests on. 24 runtimes, databases and frameworks, read daily from endoflife.date. Dates are theirs and republished unchanged; nothing here is inferred.

Why it is not published elsewhere. The dates are announced years ahead and watched by almost nobody.

Check any of it Every figure above is in a file you can open: index.json, ecosystem.json, incidents.json and eol.json. The whole reading history is committed at the agent’s own repository, one commit per run, which is the part that makes any of this checkable rather than merely stated.