Source Verification
1. Headline claims
| Claim in the report | Figure | How to verify |
|---|---|---|
| Typical vendor sees ~79% of usage on an outdated version | 78.8% (median of 32) | Section 2 below — per-vendor figures with links; median across the 32 rows |
| Median version running in production is 376 days old | 378 days | Section 2, 'median age' column; each row checkable against the linked version history |
| 23 of 32 vendors have most usage on outdated versions | 23 of 32 | Section 2 — count the rows above 50% |
| 355.7 million installations measured | 355,709,137 | Sum of the download-count links in Section 2 |
| 6,205 releases scanned, 731 flagged | 6,205 / 731 | Section 3 — release pages linked per vendor |
| 1,234 public discussions from 767 engineers, 31% unresolved | 1,234 / 767 / 377 | Section 4 — all 38 searches linked, re-runnable |
| 144 higher-confidence discussions from 119 engineers | 144 / 119 | Section 4 — individual discussions linked |
2. Version usage — all 32 vendors
Two links per vendor. Live counts returns the raw per-version download data for the trailing week — the exact primary source. Version history shows publication dates in readable form, so the age figures can be checked.
| Vendor | Package measured | % outdated | Median age | Slowest 10% | Verify |
|---|---|---|---|---|---|
| Google APIs | googleapis | 100.0% | 699d | 1491d | live counts · version history |
| Linear | @linear/sdk | 99.7% | 208d | 825d | live counts · version history |
| OpenAI | openai | 99.0% | 227d | 467d | live counts · version history |
| DocuSign | docusign-esign | 98.1% | 707d | 1699d | live counts · version history |
| Auth0 | auth0 | 97.0% | 270d | 1053d | live counts · version history |
| Square | square | 96.4% | 591d | 747d | live counts · version history |
| Pinecone | @pinecone-database/pinecone | 95.8% | 467d | 1201d | live counts · version history |
| Plaid | plaid | 95.5% | 528d | 1020d | live counts · version history |
| Slack | @slack/web-api | 94.0% | 251d | 920d | live counts · version history |
| Anthropic (0.x — measured on minor) | @anthropic-ai/sdk | 93.6% | 101d | 522d | live counts · version history |
| HubSpot | @hubspot/api-client | 92.5% | 466d | 1287d | live counts · version history |
| Segment | @segment/analytics-node | 90.3% | 677d | 936d | live counts · version history |
| Firebase | firebase-admin | 87.9% | 340d | 984d | live counts · version history |
| Twilio | twilio | 84.8% | 375d | 1300d | live counts · version history |
| Mux | @mux/mux-node | 79.1% | 475d | 1893d | live counts · version history |
| MongoDB | mongodb | 78.8% | 426d | 1139d | live counts · version history |
| GitHub | @octokit/rest | 78.3% | 535d | 1768d | live counts · version history |
| Stripe | stripe | 72.2% | 341d | 1088d | live counts · version history |
| Shopify | @shopify/shopify-api | 66.9% | 378d | 1048d | live counts · version history |
| Notion | @notionhq/client | 63.1% | 508d | 1599d | live counts · version history |
| Clerk | @clerk/clerk-sdk-node | 58.9% | 571d | 984d | live counts · version history |
| Contentful | contentful | 52.7% | 683d | 1519d | live counts · version history |
| Sentry | @sentry/node | 50.8% | 259d | 1239d | live counts · version history |
| LangChain | langchain | 43.7% | 208d | 651d | live counts · version history |
| Algolia | algoliasearch | 26.9% | 285d | 1250d | live counts · version history |
| SendGrid | @sendgrid/mail | 25.6% | 483d | 1538d | live counts · version history |
| Resend | resend | 25.3% | 105d | 382d | live counts · version history |
| PostHog | posthog-node | 21.3% | 145d | 438d | live counts · version history |
| Supabase | @supabase/supabase-js | 0.1% | 87d | 382d | live counts · version history |
| Datadog | @datadog/datadog-api-client | 0.0% | 413d | 1022d | live counts · version history |
| Temporal | @temporalio/client | 0.0% | 80d | 447d | live counts · version history |
| AWS SDK | @aws-sdk/client-s3 | 0.0% | 132d | 698d | live counts · version history |
"8.222.0": 41523 — that version was installed 41,523 times in the trailing week. Sum the entries whose leading number is below the current one, divide by the total, and you have the ‘% outdated’ column. The current version is shown at the top of the version-history page.3. Breaking-change frequency
Rates cover the 27 vendors measurable cleanly. Each release page below is the vendor's own published announcement history — the wording quoted in the report is theirs, not a paraphrase.
| Vendor | Breaking/yr | Share | Releases sampled | Verify |
|---|---|---|---|---|
| Linear | 17.3 | 34.4% | 270 | all releases · example: @linear/sdk@89 |
| Sentry | 13.2 | 12.0% | 300 | all releases · example: 10.56.0 |
| Twilio | 9.8 | 42.0% | 257 | all releases · example: 6.0.0 |
| Shopify | 6.1 | 7.9% | 76 | all releases · example: @shopify/store |
| Stripe | 5.1 | 5.7% | 300 | all releases · example: v22.1.0-alpha. |
| Temporal | 4.4 | 17.3% | 75 | all releases · example: v1.21.0 |
| GitHub | 3.1 | 4.7% | 300 | all releases · example: v22.0.0 |
| Slack | 3.0 | 8.3% | 300 | all releases · example: @slack/webhook |
| Anthropic | 2.9 | 2.7% | 300 | all releases · example: aws-sdk-v0.6.1 |
| AWS SDK | 2.4 | 1.0% | 300 | all releases · example: v3.1095.0 |
| OpenAI | 2.3 | 2.0% | 300 | all releases · example: v7.0.0 |
| Pinecone | 2.2 | 17.9% | 39 | all releases · example: v8.0.0 |
| Mux | 1.4 | 10.6% | 104 | all releases · example: v13.0.0 |
| HubSpot | 1.3 | 10.7% | 75 | all releases · example: 14.0.0 |
The five vendors excluded from this calculation
Each publishes a separate release per internal component, so a 300-release sample spans weeks instead of years and any annual rate computed from it is an artefact. They remain in Section 2, which is unaffected.
- Google APIs — 300 releases in 66 days · see for yourself
- Clerk — 300 releases in 30 days · see for yourself
- Supabase — 300 releases in 258 days · see for yourself
- LangChain — 300 releases in 154 days · see for yourself
- Datadog — 300 releases in 194 days · see for yourself
4. Evidence of harm
4a. The searches — all 38, re-runnable
Clicking any of these runs the same search live. Result counts will exceed what the research kept: only the 40 most-engaged per search were collected, then de-duplicated and filtered.
| Vendor | Search phrase | Run it |
|---|---|---|
| Stripe | stripe api version | run search |
| Stripe | stripe breaking | run search |
| Twilio | twilio breaking change | run search |
| Plaid | plaid api version | run search |
| OpenAI | openai v4 migration | run search |
| OpenAI | openai breaking change | run search |
| Anthropic | anthropic sdk breaking | run search |
| Shopify | shopify api version deprecat | run search |
| Slack | slack api deprecat | run search |
| SendGrid | sendgrid breaking | run search |
| Segment | segment analytics migration | run search |
| Auth0 | auth0 breaking change | run search |
| HubSpot | hubspot api deprecat | run search |
| Square | square api version | run search |
| Mux | mux api breaking | run search |
| Clerk | clerk breaking change | run search |
| Supabase | supabase v2 migration | run search |
| Algolia | algolia v5 migration | run search |
| Contentful | contentful breaking | run search |
| Datadog | datadog api deprecat | run search |
| Pinecone | pinecone breaking change | run search |
| Temporal | temporal sdk breaking | run search |
| LangChain | langchain breaking change | run search |
| AWS SDK | aws sdk v2 v3 migration | run search |
| Google APIs | google api deprecat | run search |
| Firebase | firebase breaking change | run search |
| Sentry | sentry v8 migration | run search |
| Notion | notion api version | run search |
| Linear | linear sdk breaking | run search |
| PostHog | posthog breaking change | run search |
| Resend | resend api change | run search |
| GitHub | octokit breaking change | run search |
| MongoDB | mongodb driver migration | run search |
| DocuSign | docusign api version | run search |
| (general) | "breaking change" "third party api" in:title,body | run search |
| (general) | "api version" "deprecated" "have to migrate" in:body | run search |
| (general) | "broke production" api in:title,body | run search |
| (general) | "upgrade guide" "took us" weeks in:body | run search |
4b. Individual discussions — the high-confidence set
144 discussions passed the distress-marker filter, from 119 engineers. The 30 most-discussed are listed; the full set is available on request.
| Vendor | Discussion | Replies | Opened | Link |
|---|---|---|---|---|
| Clerk | Upgrade to Core 2 markjaquith/clerk-sveltekit | 64 | 2024-06-13 | open |
| GitHub | [Snyk] Security upgrade octokit from 2.1.0 to 3.1.2 https-quantumblockchainai-atlassian-net/backstage | 19 | 2025-07-20 | open |
| OpenAI | 4.40.0 -> 4.40.1: Breaking change - OpenAI is not a constructor openai/openai-node | 18 | 2024-05-02 | open |
| Sentry | Replacement for Handlers.requestHandler, Handlers.errorHandler, etc. getsentry/sentry-javascript | 17 | 2024-05-13 | open |
| PostHog | chore(deps): upgrade dependencies abhi-kr-2100/CatLauncher | 14 | 2026-05-03 | open |
| AWS SDK | Client Lambda local invocation issue aws/aws-sdk-js-v3 | 13 | 2024-02-26 | open |
| Firebase | Update Dependency to Firebase Functions v6 firebase/firebase-functions-test | 12 | 2024-09-23 | open |
| Stripe | feat(payments): migrate from LemonSqueezy to Stripe AutumnsGrove/Lattice | 10 | 2026-02-02 | open |
| PostHog | Upgrade Dependencies to Latest Major Versions abhi-kr-2100/CatLauncher | 10 | 2026-03-18 | open |
| OpenAI | Upgrade dependencies to latest stable versions Nairon-AI/yugen | 9 | 2025-12-27 | open |
| OpenAI | Regression: ChatCompletionToolParam no longer a valid type in 1.99.2 openai/openai-python | 8 | 2025-08-07 | open |
| Auth0 | feat!: rename credentials mode "auth0" to "oauth" arkorlab/arkor | 8 | 2026-07-10 | open |
| MongoDB | Add support for mongo-driver v2 without breaking 1.x compatibility golang-migrate/migrate | 8 | 2025-04-28 | open |
| Stripe | bump: upgrade stripe to v20.0.0 giselles-ai/giselle | 8 | 2025-11-21 | open |
| Clerk | Upgrade Convex Clerk integration to Clerk Core 3 (`@clerk/react` v6) get-convex/convex-backend | 8 | 2026-03-13 | open |
| Segment | React query and react context conversion openedx/frontend-app-learner-dashboard | 7 | 2026-01-30 | open |
| Segment | Migrate GoCardless checkout from Redirect Flows to Billing Request Flows tojemoc/vmp | 7 | 2026-05-08 | open |
| Twilio | fix: axios alert CityOfDetroit/bloom | 6 | 2026-04-13 | open |
| OpenAI | feat: OpenAICompatibleProvider — native OpenAI SDK provider with CRUD settings protoLabsAI/protoMaker | 6 | 2026-02-27 | open |
| Segment | chore(runway): cherry-pick feat(perps): force unified account MetaMask/metamask-mobile | 6 | 2026-05-04 | open |
| LangChain | feat: support langchain v1 NVIDIA-NeMo/Guardrails | 5 | 2025-10-24 | open |
| MongoDB | Motor -> Async PyMongo art049/odmantic | 5 | 2025-05-18 | open |
| Notion | chore: maintenance batch — Notion migration, DocCard re-swizzle, regression te digidem/comapeo-docs | 5 | 2026-06-19 | open |
| OpenAI | Upgrade AI SDK and its providers browserbase/stagehand | 5 | 2026-02-16 | open |
| Resend | fix: simplify auth to OTP/OAuth only, default new users to admin nuancedtire/aide | 5 | 2026-02-16 | open |
| Twilio | fix: axios alert bloom-housing/bloom | 5 | 2026-04-13 | open |
| Segment | feat(perps): force unified account MetaMask/metamask-mobile | 5 | 2026-04-29 | open |
| GitHub | chore: Upgrade octokit/rest.js for CVE patch danger/danger-js | 4 | 2025-02-20 | open |
| Stripe | [16.x] Upgrade Guides laravel/cashier-stripe | 4 | 2025-08-19 | open |
| LangChain | [chore] Remove langchain callback handler integration streamlit/streamlit | 4 | 2026-05-05 | open |
5. Claims that are estimates, not measurements
These have no external source because none exists. They are arithmetic built on the measured figures above, and are labelled as estimates in the report itself. Listed here so nobody mistakes them for findings.
| Claim | What it rests on |
|---|---|
| Older, larger vendors fall further behind | A pattern visible in Section 2, not a tested statistical relationship. Directionally consistent across 32 vendors; not established as causal. |
6. Reproducing the whole thing
The collection scripts and raw outputs are kept with the project, not hosted here — email me and I'll send them. Each script reads one vendor list and writes CSVs; no manual steps, no hand-entered numbers.
| Script | What it produces |
|---|---|
vendors.py | The 32-vendor list every script reads |
npm_version_lag.py | Section 2 — version_lag.csv, version_lag_summary.csv |
github_releases_breaking.py | Section 3 — releases.csv, releases_summary.csv |
github_pain_mining.py | Section 4 — pain_issues.csv |
data/ | All raw outputs, one row per version / release / discussion |
Both GitHub scripts need a personal access token with public read scope. The npm script needs nothing.