Skip to content

Feature: New check for average time to update dependencies #2458

@olivekl

Description

@olivekl

Proposal for a new check: project’s mean time to update (MTTU) — what is the average number of days it takes a project to update to a new version of a dependency?

The recent Sonatype State of the Supply Chain report states that 6 out of 7 vulnerabilities are transitive. The report says that “Two critical factors for reducing the risk of transitive vulnerabilities are minimizing the total number of dependencies and maintaining low update times.”

The MTTU check would give consumers an easy way to judge the risk of transitive vulnerabilities in their dependencies.

Potentially it could be combined with a check that uses deps.dev data to also give the total number of dependencies a project uses.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    Backlog - New Checks

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions