Sighttrue
Last reading 2026-09-02 04:32 UTC age unavailable without scripting

Take the reading, and check it.

Licences change. Runtimes go unsupported. Packages that look busy have not shipped in a year. This reads all of it every 4 hours and publishes every figure as a file you can check.

What it is reading right now

Not a summary. These are rows from the published data, redrawn every four hours.

Packages whose repository is still being worked on — 182 read across six registries
Package Registry Published from Last release Days since
bellman crates zkcrypto/bellman 2023-03-20 1,262
redux npm reduxjs/redux 2023-12-23 984
rocket crates rwf2/Rocket 2024-05-23 832
httpx pypi encode/httpx 2024-12-06 635
xunit nuget xunit/xunit 2025-01-08 602
jekyll gem jekyll/jekyll 2025-01-29 581
flair pypi flairNLP/flair 2025-02-05 574
@uniswap/v4-core npm Uniswap/v4-core 2025-05-13 477
openai-whisper pypi openai/whisper 2025-06-26 433
halmos pypi a16z/halmos 2025-07-31 398
bootstrap npm twbs/bootstrap 2025-08-26 372
Newtonsoft.Json nuget JamesNK/Newtonsoft.Json 2025-09-16 351
pundit gem varvet/pundit 2025-09-24 343
@coral-xyz/anchor npm coral-xyz/anchor 2025-10-10 327
sinatra gem sinatra/sinatra 2025-10-10 327

Read from the registry, not the repository. A long gap is not abandonment — a finished library is finished. Everything measured

Something it found

Stated from the published data with the figures filled in, so it cannot drift from what was measured.

98 of 416 widely used projects rest half their history on one person.

Contributor histories of 416 repositories, read weekly from GitHub. Commit count is not contribution, and this is history rather than the present.

Everything else it found

What it answers

Four questions a repository page cannot answer, because the answers are not on GitHub.

Has anybody actually shipped this?

Read from the registry, not from the last commit. A push is what a maintainer does for themselves; a release is what reaches you.

See the readings

How many people would it survive losing?

Contributors accounting for half the commits. Every other health signal measures activity; none measures who is producing it.

See the readings

When does it stop getting security fixes?

End-of-life dates are published years ahead and watched by almost nobody. A team learns its runtime went unsupported when an auditor tells them.

See the readings

Does the thing I depend on go down?

Provider incident history, kept after their own status pages drop it. Ask how often something failed last year and nobody has the record.

See the readings

Ways in

What is behind it

417Repositories
850Incidents kept after the feeds dropped them
524Release lines on the end-of-life clock
416Commit histories, for the bus factor
182Packages, by real ship date
123Names one keystroke from a real package

The watchlist is curated and partial — chosen by hand, not a survey of open source. It says so on every page that counts from it.

The instrument itself Point it at your own stack How it works, and what it cannot do