"An exploit is proof by construction that your target system has unintended behaviors."
Sergey Bratus, Paul's Security Weekly #816, 2026-02-08By the time you hear about an exploit, you're already 11 days too late. Seal Security measured the gap between fix-commit and advisory: median 11 days, 167 days for Maven. GreyNoise measured the gap between exploit-scan surge and advisory: also 11 days, with 28.96% of 2025 KEVs exploited on or before publication day. Two independent research findings, two different sides of the system, the same gap. The advisory is the lagging indicator.
VCRI's inaugural State of Supply Chain adds a third measurement: when the next vulnerability lands, is anyone home to patch it? The headline number: more than half of Go's dependent-pull volume, weighted by how many repos depend on each package, lands on packages whose maintainers have stopped responding.
Read the report
Two Clocks (PDF)
Full Q2 2026 report. Print-ready, citable, locked content. Recommended for archive and distribution.
Two Clocks (HTML)
Browser-readable version with live links and anchored sections. Best for screen reading and reference.
Companion resources
Data dashboard
Critical 16, Concerns 210, Watch 140. Browse and download the full intersection CSVs.
Q3 roadmap
Six public commitments for the Q3 issue and beyond. Anchored accountability.
Methodology & corrections
GitHub repo for methodology docs, intersection CSVs, and public issue tracker. Critique welcome.
Companion essay
"Three Eras of Zero-Day Economics" by Cairn Viktor. The story behind the numbers.
What the report contains
- Cross-ecosystem risk-weighted abandonment table covering Go, NuGet, Ruby, Maven, Cargo, PyPI, Packagist (plus an npm light-rigor preview)
- The "out-of-band and previously compromised" intersection list: every package across all ecosystems that is both out-of-band and carries OSV.dev compromise history
- Verified top-by-dependents analysis with the framing pivot story (why "abandoned" was wrong and "out-of-band" is right)
- Maven's special case: highest fix-to-advisory gap, highest concentration of out-of-band top-dependencies
- The time-series gap: OSSF Criticality Score stopped publishing snapshots in July 2025; VCRI commits to picking up the cadence from Q3 forward
- Implications for procurement and SCA tooling, regulators, registry operators, and the open-source maintainer ecosystem
- Full intersection-list CSV and the query code that produced it, published under CC BY 4.0 alongside the report
Q3 publishes early August 2026
VCRI publishes State of Supply Chain quarterly. Six public commitments are documented in the Q3 roadmap, including npm at full-rigor parity, manual top-100 verification per ecosystem, the first quarter-over-quarter delta analysis, and the monthly OSSF Criticality Score refresh.
Subscribe to the SCSC newsletter for one email per issue (no other contact). Critique and corrections are welcomed in the GitHub issue tracker and acknowledged in the next issue.