Record in aggregate · metrics 2.10.0

The state of RubyGems.

Aggregate statistics across every inspected repository publishing to RubyGems — how health distributes, where the download volume sits, and which practices are common or rare, measured against the whole record.

Inspected repositories
3,149 of 3,149 indexed
Monthly downloads under inspection
1.4B registry-reported
Median health index
62 Moderate
Good or better
46% index 65 and above

Health-index distribution

Latest health index of every inspected repository, in five-point intervals over the 1–100 scale.

Where the download volume sits

Combined monthly downloads by band, against repository counts.

20% of the monthly download volume under inspection flows through repositories below the good band — and the top 1% most-downloaded repositories carry 95% of the entire volume.

Repositories
20%21%23%16%
Download volume
38%41%16%
BandRepositoriesDownloads / moVolume share
Exceptional182526M38%
Excellent615570M41%
Good66718.4M1.3%
Moderate74017M1.2%
Weak50656.6K0.0%
At Risk323225M16%
Critical11638.5M2.8%

Score shapes

The distribution behind each category median, in ten-point bins — where the record clusters, and where a category separates repositories or saturates.

Vitality62
1100
Community & Adoption58
1100
Sustainability & Governance65
1100
Engineering Quality64
1100
Security48
1100
AI Readiness38
1100

Category profile

Median category score across the scope. Ticks mark the whole-record median. Categories are documented in the methodology wiki.

Vitality
62
Community & Adoption
58
Sustainability & Governance
65
Engineering Quality
64
Security
48
AI Readinessunweighted
38

The state of practice

Share of inspected repositories where the practice is publicly evident. Reports that predate a signal are excluded from its basis, never counted as missing.

Engineering & community practice

README
96% of 3,149
Automated tests
95% of 3,149
License detected
94% of 3,149
CI workflows
81% of 3,149
Linter configuration
57% of 3,149
Contributing guide
36% of 3,149
Code of conduct
29% of 3,149
Documentation directory
28% of 3,149
Security policy
15% of 3,149

Agent-era signals

AI agent instructions
17% of 3,149
One-command bootstrap
14% of 3,149
llms.txt
3.0% of 3,149

Signals read by the unweighted AI Readiness category.

Does popularity mean health?

Median health index (dot) and the middle half of repositories (band) per popularity bracket, on the shared 1–100 scale.

By GitHub stars

Under 100 stars 1,685
59 · 44–73
100 – 999 877
62 · 47–81
1,000 – 9,999 519
75 · 56–88
10,000 and more 68
92 · 83–96

By monthly downloads

Under 10K / month 129
65 · 51–81
10K – 1M 111
83 · 67–90
1M – 100M 46
92 · 80–95
100M and more 4
84 · 44–94

Security under the microscope

Average OpenSSF Scorecard result per check across the scope, weakest first, on Scorecard's 0–10 scale. Check results are mostly all-or-nothing, so the average tracks how much of the record passes. Checks Scorecard reports inconclusive are excluded from scoring, never counted as zero; each row's tooltip carries its basis.

CII-Best-Practices
0.0
Fuzzing
0.1
Signed-Releases
0.6
Branch-Protection
1.0
SAST
1.3
Pinned-Dependencies
1.6
Token-Permissions
2.0
Security-Policy
2.3
Code-Review
2.7
Dependency-Update-Tool
4.4
Maintained
5.0
CI-Tests
5.3
Vulnerabilities
7.9
Contributors
8.0
License
9.3
Binary-Artifacts
9.7
Dangerous-Workflow
9.9
Packaging
10.0

Red flags

Findings that adjust a rating downward rather than scoring into it. Each is reported as a count, as a share of the whole record, and as a rate among the repositories where it could be determined at all.

Abandonment
2959.4% of the record · 9.4% of 3,149 assessed
High-risk jurisdiction exposure
321.0% of the record · 1.1% of 3,024 assessed
Inorganic growth
150.5% of the record · 4.6% of 329 assessed
Malicious dependencies
30.1% of the record · 0.3% of 1,038 assessed

A red flag needs its own evidence, so its basis is smaller than the record. Growth authenticity is assessed only where day-by-day history was collected; dependency findings only where a dependency graph resolved. Repositories the evidence cannot answer for are left out of the basis rather than counted as passing.

The pulse

How recently each inspected repository last saw a push, at inspection time.

Half of the inspected repositories saw a push within 6 days of inspection.

Push recency
63%19%
Last pushRepositoriesShare
Pushed within 30 days1,98863%
31 – 90 days2457.8%
91 – 365 days33111%
Over a year58519%

Stewardship & resilience

Who stands behind the inspected repositories, and how many people the code depends on. Both are read by the governance category.

1,995Organization-stewarded median 69
1,154Personal accounts median 53

Maintainer bus factor

66% of inspected repositories depend on a single maintainer for the majority of their commits — including 23 with over a million monthly downloads.

1 maintainer
2,065
2 maintainers
683
3–5 maintainers
340
6+ maintainers
58

The dependency iceberg

Declared direct dependencies against the full resolved graph (direct plus transitive), across the 2,890 reports with a collected dependency graph.

The median repository declares 2 direct dependencies — and resolves to 15 packages in total.

Resolved packages per repository

0
70
1 – 5
462
6 – 20
1,132
21 – 50
392
51 – 200
485
201 – 500
123
501 – 1,000
70
Over 1,000
156

License landscape

The most common detected licenses across the scope (SPDX identifiers).

MIT
1,884
Custom license
450
Apache-2.0
356
No license detected
175
BSD-2-Clause
72
GPL-3.0
42
BSD-3-Clause
40
GPL-2.0
35
AGPL-3.0
28
CC0-1.0
14

Most relied upon

The most-downloaded repositories under inspection publishing to RubyGems — the records the figures above weigh heaviest. The rest is covered by the full catalogue · tag index.

npm · RubyGems
32At Riskhealth index
petkaantonov/bluebird
:bird: :zap: Bluebird is a full featured promise library with unmatched performance.
JavaScript★ 20.5K↓ 217M/moAug 12, 2026
MITAug 12, 2026 · metrics 2.10.0
npm · RubyGems
80Excellenthealth index
dsherret/ts-morph
TypeScript Compiler API wrapper for static analysis and programmatic code changes.
TypeScript★ 6,153↓ 187M/moAug 12, 2026
MITAug 12, 2026 · metrics 2.10.0
npm · Maven · RubyGems
96Exceptionalhealth index
react/react-native
A framework for building native applications using React
C++ · Kotlin · JavaScript★ 126.3K↓ 178M/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
npm · RubyGems · Packagist
87Excellenthealth index
handlebars-lang/handlebars.js
Minimal templating on steroids.
JavaScript★ 18.7K↓ 168M/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
npm · crates.io · RubyGems
96Exceptionalhealth index
facebook/flow
Adds static typing to JavaScript to improve developer productivity and code quality.
Rust · JavaScript★ 22.3K↓ 69.8M/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
crates.io · RubyGems
80Excellenthealth index
GREsau/schemars
Generate JSON Schema documents from Rust code
Rust★ 1,396↓ 61.8M/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0

Reading these figures

  • Every figure is computed from the latest published inspection of each repository, under the versioned methodology (currently metrics 2.10.0). See the methodology · band scale.
  • Statistics describe the inspected record — software admitted for inspection, not a random sample of all open source. Admission follows the public-interest criteria.
  • Download figures come from package registries; registries that publish no monthly number (Maven Central, Go, NuGet, RubyGems) contribute no volume rather than zero. Coverage per ecosystem is documented in supported ecosystems.
  • Where a signal is unavailable in a report — an uncollected dependency graph, an inconclusive Scorecard check, a report predating a signal — the repository is excluded from that figure's basis, never counted against it.
  • Health indices are signals of publicly visible practice, not audits or warranties — how to read them is covered by the health index.
  • Figures computed 2026-09-06 09:17 UTC; the aggregate is recomputed hourly. The underlying data is available as JSON.