Source Verification

Every figure in The One-Year Gap, with a live link to check it. Data collected 3–7 August 2026.
Download the report (PDF)
How to use thisLinks go to the same public endpoints the research read. Two caveats worth knowing before you click: the live figures will have moved since collection — vendors publish continuously, so expect small drift, not different conclusions. And the download-count links return raw JSON, which is dense but is the actual primary source; the npm version-history links next to them show the same information in a readable page.

1. Headline claims

Claim in the reportFigureHow to verify
Typical vendor sees ~79% of usage on an outdated version78.8% (median of 32)Section 2 below — per-vendor figures with links; median across the 32 rows
Median version running in production is 376 days old378 daysSection 2, 'median age' column; each row checkable against the linked version history
23 of 32 vendors have most usage on outdated versions23 of 32Section 2 — count the rows above 50%
355.7 million installations measured355,709,137Sum of the download-count links in Section 2
6,205 releases scanned, 731 flagged6,205 / 731Section 3 — release pages linked per vendor
1,234 public discussions from 767 engineers, 31% unresolved1,234 / 767 / 377Section 4 — all 38 searches linked, re-runnable
144 higher-confidence discussions from 119 engineers144 / 119Section 4 — individual discussions linked

2. Version usage — all 32 vendors

Two links per vendor. Live counts returns the raw per-version download data for the trailing week — the exact primary source. Version history shows publication dates in readable form, so the age figures can be checked.

VendorPackage measured% outdatedMedian ageSlowest 10%Verify
Google APIsgoogleapis100.0%699d1491dlive counts · version history
Linear@linear/sdk99.7%208d825dlive counts · version history
OpenAIopenai99.0%227d467dlive counts · version history
DocuSigndocusign-esign98.1%707d1699dlive counts · version history
Auth0auth097.0%270d1053dlive counts · version history
Squaresquare96.4%591d747dlive counts · version history
Pinecone@pinecone-database/pinecone95.8%467d1201dlive counts · version history
Plaidplaid95.5%528d1020dlive counts · version history
Slack@slack/web-api94.0%251d920dlive counts · version history
Anthropic (0.x — measured on minor)@anthropic-ai/sdk93.6%101d522dlive counts · version history
HubSpot@hubspot/api-client92.5%466d1287dlive counts · version history
Segment@segment/analytics-node90.3%677d936dlive counts · version history
Firebasefirebase-admin87.9%340d984dlive counts · version history
Twiliotwilio84.8%375d1300dlive counts · version history
Mux@mux/mux-node79.1%475d1893dlive counts · version history
MongoDBmongodb78.8%426d1139dlive counts · version history
GitHub@octokit/rest78.3%535d1768dlive counts · version history
Stripestripe72.2%341d1088dlive counts · version history
Shopify@shopify/shopify-api66.9%378d1048dlive counts · version history
Notion@notionhq/client63.1%508d1599dlive counts · version history
Clerk@clerk/clerk-sdk-node58.9%571d984dlive counts · version history
Contentfulcontentful52.7%683d1519dlive counts · version history
Sentry@sentry/node50.8%259d1239dlive counts · version history
LangChainlangchain43.7%208d651dlive counts · version history
Algoliaalgoliasearch26.9%285d1250dlive counts · version history
SendGrid@sendgrid/mail25.6%483d1538dlive counts · version history
Resendresend25.3%105d382dlive counts · version history
PostHogposthog-node21.3%145d438dlive counts · version history
Supabase@supabase/supabase-js0.1%87d382dlive counts · version history
Datadog@datadog/datadog-api-client0.0%413d1022dlive counts · version history
Temporal@temporalio/client0.0%80d447dlive counts · version history
AWS SDK@aws-sdk/client-s30.0%132d698dlive counts · version history
Reading the raw countsThe live-counts link returns one entry per version, e.g. "8.222.0": 41523 — that version was installed 41,523 times in the trailing week. Sum the entries whose leading number is below the current one, divide by the total, and you have the ‘% outdated’ column. The current version is shown at the top of the version-history page.

3. Breaking-change frequency

Rates cover the 27 vendors measurable cleanly. Each release page below is the vendor's own published announcement history — the wording quoted in the report is theirs, not a paraphrase.

VendorBreaking/yrShareReleases sampledVerify
Linear17.334.4%270all releases · example: @linear/sdk@89
Sentry13.212.0%300all releases · example: 10.56.0
Twilio9.842.0%257all releases · example: 6.0.0
Shopify6.17.9%76all releases · example: @shopify/store
Stripe5.15.7%300all releases · example: v22.1.0-alpha.
Temporal4.417.3%75all releases · example: v1.21.0
GitHub3.14.7%300all releases · example: v22.0.0
Slack3.08.3%300all releases · example: @slack/webhook
Anthropic2.92.7%300all releases · example: aws-sdk-v0.6.1
AWS SDK2.41.0%300all releases · example: v3.1095.0
OpenAI2.32.0%300all releases · example: v7.0.0
Pinecone2.217.9%39all releases · example: v8.0.0
Mux1.410.6%104all releases · example: v13.0.0
HubSpot1.310.7%75all releases · example: 14.0.0

The five vendors excluded from this calculation

Each publishes a separate release per internal component, so a 300-release sample spans weeks instead of years and any annual rate computed from it is an artefact. They remain in Section 2, which is unaffected.

4. Evidence of harm

4a. The searches — all 38, re-runnable

Clicking any of these runs the same search live. Result counts will exceed what the research kept: only the 40 most-engaged per search were collected, then de-duplicated and filtered.

VendorSearch phraseRun it
Stripestripe api versionrun search
Stripestripe breakingrun search
Twiliotwilio breaking changerun search
Plaidplaid api versionrun search
OpenAIopenai v4 migrationrun search
OpenAIopenai breaking changerun search
Anthropicanthropic sdk breakingrun search
Shopifyshopify api version deprecatrun search
Slackslack api deprecatrun search
SendGridsendgrid breakingrun search
Segmentsegment analytics migrationrun search
Auth0auth0 breaking changerun search
HubSpothubspot api deprecatrun search
Squaresquare api versionrun search
Muxmux api breakingrun search
Clerkclerk breaking changerun search
Supabasesupabase v2 migrationrun search
Algoliaalgolia v5 migrationrun search
Contentfulcontentful breakingrun search
Datadogdatadog api deprecatrun search
Pineconepinecone breaking changerun search
Temporaltemporal sdk breakingrun search
LangChainlangchain breaking changerun search
AWS SDKaws sdk v2 v3 migrationrun search
Google APIsgoogle api deprecatrun search
Firebasefirebase breaking changerun search
Sentrysentry v8 migrationrun search
Notionnotion api versionrun search
Linearlinear sdk breakingrun search
PostHogposthog breaking changerun search
Resendresend api changerun search
GitHuboctokit breaking changerun search
MongoDBmongodb driver migrationrun search
DocuSigndocusign api versionrun search
(general)"breaking change" "third party api" in:title,bodyrun search
(general)"api version" "deprecated" "have to migrate" in:bodyrun search
(general)"broke production" api in:title,bodyrun search
(general)"upgrade guide" "took us" weeks in:bodyrun search

4b. Individual discussions — the high-confidence set

144 discussions passed the distress-marker filter, from 119 engineers. The 30 most-discussed are listed; the full set is available on request.

VendorDiscussionRepliesOpenedLink
ClerkUpgrade to Core 2
markjaquith/clerk-sveltekit
642024-06-13open
GitHub[Snyk] Security upgrade octokit from 2.1.0 to 3.1.2
https-quantumblockchainai-atlassian-net/backstage
192025-07-20open
OpenAI4.40.0 -> 4.40.1: Breaking change - OpenAI is not a constructor
openai/openai-node
182024-05-02open
SentryReplacement for Handlers.requestHandler, Handlers.errorHandler, etc.
getsentry/sentry-javascript
172024-05-13open
PostHogchore(deps): upgrade dependencies
abhi-kr-2100/CatLauncher
142026-05-03open
AWS SDKClient Lambda local invocation issue
aws/aws-sdk-js-v3
132024-02-26open
FirebaseUpdate Dependency to Firebase Functions v6
firebase/firebase-functions-test
122024-09-23open
Stripefeat(payments): migrate from LemonSqueezy to Stripe
AutumnsGrove/Lattice
102026-02-02open
PostHogUpgrade Dependencies to Latest Major Versions
abhi-kr-2100/CatLauncher
102026-03-18open
OpenAIUpgrade dependencies to latest stable versions
Nairon-AI/yugen
92025-12-27open
OpenAIRegression: ChatCompletionToolParam no longer a valid type in 1.99.2
openai/openai-python
82025-08-07open
Auth0feat!: rename credentials mode "auth0" to "oauth"
arkorlab/arkor
82026-07-10open
MongoDBAdd support for mongo-driver v2 without breaking 1.x compatibility
golang-migrate/migrate
82025-04-28open
Stripebump: upgrade stripe to v20.0.0
giselles-ai/giselle
82025-11-21open
ClerkUpgrade Convex Clerk integration to Clerk Core 3 (‎`@clerk/react` v6)
get-convex/convex-backend
82026-03-13open
SegmentReact query and react context conversion
openedx/frontend-app-learner-dashboard
72026-01-30open
SegmentMigrate GoCardless checkout from Redirect Flows to Billing Request Flows
tojemoc/vmp
72026-05-08open
Twiliofix: axios alert
CityOfDetroit/bloom
62026-04-13open
OpenAIfeat: OpenAICompatibleProvider — native OpenAI SDK provider with CRUD settings
protoLabsAI/protoMaker
62026-02-27open
Segmentchore(runway): cherry-pick feat(perps): force unified account
MetaMask/metamask-mobile
62026-05-04open
LangChainfeat: support langchain v1
NVIDIA-NeMo/Guardrails
52025-10-24open
MongoDBMotor -> Async PyMongo
art049/odmantic
52025-05-18open
Notionchore: maintenance batch — Notion migration, DocCard re-swizzle, regression te
digidem/comapeo-docs
52026-06-19open
OpenAIUpgrade AI SDK and its providers
browserbase/stagehand
52026-02-16open
Resendfix: simplify auth to OTP/OAuth only, default new users to admin
nuancedtire/aide
52026-02-16open
Twiliofix: axios alert
bloom-housing/bloom
52026-04-13open
Segmentfeat(perps): force unified account
MetaMask/metamask-mobile
52026-04-29open
GitHubchore: Upgrade octokit/rest.js for CVE patch
danger/danger-js
42025-02-20open
Stripe[16.x] Upgrade Guides
laravel/cashier-stripe
42025-08-19open
LangChain[chore] Remove langchain callback handler integration
streamlit/streamlit
42026-05-05open

5. Claims that are estimates, not measurements

These have no external source because none exists. They are arithmetic built on the measured figures above, and are labelled as estimates in the report itself. Listed here so nobody mistakes them for findings.

ClaimWhat it rests on
Older, larger vendors fall further behindA pattern visible in Section 2, not a tested statistical relationship. Directionally consistent across 32 vendors; not established as causal.

6. Reproducing the whole thing

The collection scripts and raw outputs are kept with the project, not hosted here — email me and I'll send them. Each script reads one vendor list and writes CSVs; no manual steps, no hand-entered numbers.

ScriptWhat it produces
vendors.pyThe 32-vendor list every script reads
npm_version_lag.pySection 2 — version_lag.csv, version_lag_summary.csv
github_releases_breaking.pySection 3 — releases.csv, releases_summary.csv
github_pain_mining.pySection 4 — pain_issues.csv
data/All raw outputs, one row per version / release / discussion

Both GitHub scripts need a personal access token with public read scope. The npm script needs nothing.