Libyear – a simple measure of software dependency freshness
libyear.com
libyear.com
The libyear metric doesn't count when the dependency was last updated by the maintainer. Its a diff of the version you're currently using compared to the latest release, to tell you how out of date your current dependencies are.
Its pretty much a dependency drift fitness function (https://www.thoughtworks.com/radar/techniques/dependency-dri...). Some of the variants on this page do support alternate metrics, like the ruby and node versions which can calculate number of releases behind rather than time.
Somehow this made it all click for me, when the landing page didn't. Site made it seem like the measure rewards absolute value recency.
edit: offending sentence is the following:
> If your system has two dependencies, the first one year old, the second three, then your system is four libyears out-of-date.
if my main project is using a core framework version from, say, 2019, and all the installed dependencies are from 2018/2019, the 'libyear' calculations are all relative to that 2019 base date, vs whatever 'now' is?
Repeat that calculation for your other dependencies, relative to their latest release date.
(linked by the author in the README's)
Lesser known libs can be riddled with vulns that nobody has found.
https://ericbouwers.github.io/papers/icse15.pdf#page=9&zoom=...
Are software metrics still useless?
Also yes.