LINUX FOUNDATION RESEARCH

We’re investigating the impact of open source collaboration to solve the world’s most pressing challenges.

LF Research about page cover tiles

About LF Research

LF Research publishes actionable and decision-useful insights into open source software, hardware, standards, and data based on empirical research methodologies. Through leveraging community networks, project databases, surveys, and qualitative findings, and through its commitment to best practices in primary research, Linux Foundation Research is the definitive home for data-driven insights into open source for the benefit of governments, enterprises, and society at large.

Census III of Free and Open Source Software

In this report, LF Research partnered with OpenSSF and the Laboratory for Innovation Science at Harvard to study the most common packages used at the application library level.

 

Census III 2024_Cover Thumbnail

Participate in Our Research

Join the LF Research Forum and participate in our surveys and interviews to give back to your community and earn events & training discounts!

Interested in conducting research?

Review our prospectus for more information, and email us at research@linuxfoundation.org

 

lfresearch_benefits

Census II of Free and Open Source Software — Application Libraries

Download Report

Abstract

Produced in partnership with Harvard Laboratory for Innovation Science (LISH) and the Open Source Security Foundation (OpenSSF), Census II is the second investigation into the widespread use of Free and Open Source Software (FOSS). The Census II effort utilizes data from partner Software Composition Analysis (SCA) companies including Snyk, the Synopsys Cybersecurity Research Center (CyRC), and FOSSA. The aggregated data includes over half a million observations of FOSS libraries used in production applications at thousands of companies, aiming to shed light on the most commonly used FOSS packages at the application library level. This effort builds on the Census I report that focused on the lower level critical operating system libraries and utilities, improving our understanding of the FOSS packages that software applications rely on. Such insights will help identify critical FOSS packages to allow resource prioritization to address security issues in this widely used software. 

Authors

  • Frank Nagle, Harvard Business School
  • James Dana, Harvard Business School 
  • Jennifer Hoffman, Laboratory for Innovation Science at Harvard
  • Steven Randazzo, Laboratory for Innovation Science at Harvard
  • Yanuo Zhou, Harvard Business School

Additional Resources

DOI: 10.70828/KHEH5209

Our Team

Filter by: