Subscribe to the State of Supply Chain
VCRI's quarterly report on open-source dependency health, abandonment, and compromise. Free under non-commercial license. The data and methodology are public.
📬 Subscribe by email
Send us a one-line email — we add you to the issue announcement list. Quarterly. No spam, no upsell, you can unsubscribe by replying STOP.
Email info@valuechainrisk.orgWhat you'll receive
- Quarterly issue announcement with a direct link to the report PDF, the data CSV, and the underlying query code.
- Mid-quarter methodology notes when meaningful refinements land (occasional, not monthly).
- Early access to the Q3 issue ahead of public publication.
What you won't receive
- Marketing emails. We don't do them.
- Third-party sharing of your address. Your address stays at VCRI.
- Sales pitches. Commercial implementation runs through Cairn Risk Co. and is opt-in via a separate path.
About the report
The State of Supply Chain (SCSC) is VCRI's outside-in measurement of open-source dependency health across eight major ecosystems. Each issue intersects maintenance state (is anyone home to patch?) with historical compromise (has this package been here before?) to produce a procurement-grade watch list. The methodology is rule-based, transparent, and criticizable; the data is published alongside each issue under CC BY-NC 4.0.
Read the inaugural companion piece, Three Eras of Zero-Day Economics, for the structural argument the Q2 issue is built on.
Note: an automated subscription form is coming. For now, the email route above is the canonical subscribe path — it gets you on the announcement list immediately. Questions to info@valuechainrisk.org.