Record in aggregate · metrics 2.10.0

The state of Go.

Aggregate statistics across every inspected repository publishing to Go — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
18,149 of 18,150 indexed
Monthly downloads under inspection
1.3B registry-reported
Median health index
56 Moderate
Good or better
34% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

20% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 100% of the entire volume.

Repositories
17%27%22%
Download volume
24%52%
BandRepositoriesDownloads / moVolume share
Exceptional767313M24%
Excellent2,35262.1M4.7%
Good3,043680M52%
Moderate4,859198M15%
Weak3,9476.2M0.5%
At Risk2,64652M4.0%
Critical535308.4K0.0%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality72
1100
Community & Adoption29
1100
Sustainability & Governance54
1100
Engineering Quality63
1100
Security44
1100
AI Readiness62
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
72
Community & Adoption
29
Sustainability & Governance
54
Engineering Quality
63
Security
44
AI Readinessunweighted
62

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

Automated tests
91% of 18,149
README
90% of 18,149
License detected
88% of 18,149
CI workflows
78% of 18,149
Linter configuration
41% of 18,149
Documentation directory
41% of 18,149
Contributing guide
29% of 18,149
Security policy
18% of 18,149
Code of conduct
17% of 18,149

Agent-era signals

One-command bootstrap
55% of 18,149
AI agent instructions
29% of 18,149
llms.txt
3.7% of 18,149

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 15,408
53 · 38–65
100 – 999 1,665
78 · 63–89
1,000 – 9,999 831
87 · 73–94
10,000 and more 245
94 · 88–98

By monthly downloads

Under 10K / month 589
62 · 51–75
10K – 1M 125
84 · 73–92
1M – 100M 55
83 · 60–94
100M and more 1
77 · 77–77

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.1
Fuzzing
1.0
Branch-Protection
1.1
Signed-Releases
1.1
Code-Review
1.7
SAST
1.8
Token-Permissions
2.0
Pinned-Dependencies
2.1
Security-Policy
2.3
Dependency-Update-Tool
4.1
Contributors
4.5
Maintained
5.2
Vulnerabilities
5.9
CI-Tests
7.3
License
8.7
Dangerous-Workflow
9.7
Binary-Artifacts
9.8
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
6173.4% of the record · 3.4% of 18,150 assessed
High-risk jurisdiction exposure
2791.5% of the record · 1.9% of 14,477 assessed
Malicious dependencies
3<0.1% of the record · <0.1% of 6,215 assessed
Inorganic growth
00% of the record · 0% of 131 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 3 days of inspection.

Push recency
87%
Last pushRepositoriesShare
Pushed within 30 days15,78987%
31 – 90 days1,1006.1%
91 – 365 days5312.9%
Over a year7294.0%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

9,399Organization-stewarded median 63
8,750Personal accounts median 48

Maintainer bus factor

81% of inspected repositories depend on a single maintainer for the majority of their commits — including 17 with over a million monthly downloads.

1 maintainer
14,526
2 maintainers
1,908
3–5 maintainers
1,170
6+ maintainers
232

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 10,006 reports with a collected dependency graph.

The median repository declares 8 direct dependencies — and resolves to 43 packages in total.

Resolved packages per repository

0
738
1 – 5
1,273
6 – 20
1,730
21 – 50
1,551
51 – 200
2,623
201 – 500
1,121
501 – 1,000
500
Over 1,000
470

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
7,572
Apache-2.0
5,093
No license detected
2,248
Custom license
1,054
GPL-3.0
504
AGPL-3.0
457
BSD-3-Clause
436
MPL-2.0
387
BSD-2-Clause
143
LGPL-3.0
63

Most relied upon

The most-downloaded repositories under inspection publishing to Go — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

npm · Go
77Goodhealth index
WebReflection/flatted
A fast and minimal circular JSON parser.
JavaScript · Go · PHP★ 1,151↓ 577M/moAug 4, 2026
ISCAug 4, 2026 · metrics 2.10.0
PyPI · npm · Go
94Exceptionalhealth index
modal-labs/modal-client
SDK libraries for Modal
Python · Go · TypeScript★ 511↓ 82.6M/moAug 27, 2026
Apache-2.0Aug 27, 2026 · metrics 2.10.0
PyPI · npm · crates.io +1
62Moderatehealth index
tree-sitter/tree-sitter-bash
Bash grammar for tree-sitter
C · JavaScript★ 327↓ 41.4M/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm · Packagist · Hex +4
95Exceptionalhealth index
cucumber/messages
A message protocol for representing results and other information from Cucumber
C# · PHP · Java★ 41↓ 34.8M/moAug 22, 2026
MITAug 22, 2026 · metrics 2.10.0
npm · PyPI · Packagist +4
98Exceptionalhealth index
svix/svix-webhooks
The open source and enterprise-ready webhooks service 🦀
Rust · C#★ 3,371↓ 34.3M/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0
npm · PyPI · Packagist +4
96Exceptionalhealth index
cucumber/gherkin
A parser and compiler for the Gherkin language.
C★ 400↓ 32.5M/moAug 27, 2026
MITAug 27, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-06 07:55 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.