Dependency hell in software supply chains

Hygiene

Ask a technology department what its software is built on, and odds are it will gesture at the codebase and announce a magnificent digital edifice. Look under the floorboards and the edifice turns out to be teetering on assorted crates, barrels and borrowed planks acquired from a thousand strangers, rather like a warehouse in Ankh-Morpork held together by hope, rust, and a prayer to any god that has not yet resigned in exasperation.

Europe runs on oceans of open source. This is excellent. It is also a sort of ongoing civic hazard, because every unmaintained module is interest accruing quietly, growing in the dark like mould in a Morporkian cellar.

The invisible foundation

Modern software is rarely crafted from scratch in the noble tradition of artisan dwarves. It is assembled the way a Morporkian entrepreneur assembles a tavern: start with a room, add bits until customers stop complaining, and hope nothing collapses during peak hours. A team might write ten thousand lines of its own code; the remaining millions arrive from strangers scattered across the multiverse, each with their own priorities, grudges, and peculiar ideas about indentation. Direct dependencies are chosen. The transitive ones choose you: install fifty packages and a thousand cousins arrive uninvited, nested twenty layers deep like an extended Morporkian family, all with opinions about dinner.

What remains is faith. Faith that someone else’s code does what it says, that it does not do what it does not say, and that the maintainers are competent and sober. That is a great deal of faith.

Budgeting for construction, not decay

Budgets are allocated for construction, seldom for the fact that software ages like fish. Year one is marvellous. By year five the application runs on dependencies old enough to vote, the known vulnerabilities could fill a report thick enough to fend off a bar brawl, and there is no budget to fix any of it. Upgrades cascade: a one line version bump can require a new framework, which breaks half the other libraries, and a quick fix becomes a seven-week expedition up a mountain of broken builds. Pinned versions promise stability and quietly fossilise; version ranges promise freshness and occasionally set production on fire at two in the morning. Weighed against shiny new features, the upgrade tends to lose, and a soothing note is written in the risk register instead.

The volunteer bedrock

The economic model of open source is simple: consumption is free, contribution is optional, maintenance is a volunteer sport. The more successful a package, the faster its maintainer seems to burn out, and when one vanishes the package does not scream; it simply goes quiet until a security announcement forces someone to look. Heartbleed and Log4Shell were not caused by incompetence. They grew out of overworked volunteers doing heroic work for no pay while industries built skyscrapers on their foundations. The same openness admits the other traffic: typosquats, hijacked accounts, and malicious packages published with nothing more than a keyboard and a slight disregard for consequences. Trust is extended liberally; revocation is hard. The marketplace has enthusiastic pickpockets and few guards.

Scanning as ritual

Security scanners are marvellous at generating reports and less marvellous at generating solutions. A typical report lists hundreds of vulnerabilities with little sense of which are exploitable in context, so the cycle often settles into ritual: scan, panic, ignore, repeat. After enough cycles the report becomes background hum, like the river Ankh. Ever present. Largely ignored.

If dependency hell had a map, it would look suspiciously like Ankh-Morpork: everything built on everything else, everything leaking into everything else, and no guarantee the bricks at the bottom are still where anyone left them. And yet here we appear to be. Still building. Still shipping.

The clerk’s brief

From the clerks, for the Patrician’s eyes

Compiled July 2026. Entries run newest first; the settled patterns sink into the foundations at the end. The clerks wish to note that everything in this file was, at some point, somebody’s convenient shortcut.

July 2026: The law is coming for the graph

Under the Cyber Resilience Act, from 11 September 2026 manufacturers are required to report actively exploited vulnerabilities in products with digital elements, with the main obligations, including a software bill of materials, following from December 2027. For the first time, an EU law makes the contents of the crates and barrels someone’s accountable responsibility. Whether accountability can be retrofitted onto a volunteer bedrock is, the clerks concede, an open experiment.

February 2026: The vulnerabilities doubled, with mechanical assistance

Black Duck’s analysis of 947 codebases, published February 2026, found the mean number of vulnerabilities per codebase jumped 107 per cent in a single year, driven partly by AI-assisted development pulling in components without review. 65 per cent of surveyed organisations reported a supply chain attack in the previous year, and about a quarter said they evaluate AI-generated code for security. The clerks observe that the industry has automated the acquisition of dependencies rather more thoroughly than the understanding of them.

January 2026: The registries keep counting

Sonatype’s state of the software supply chain report, published January 2026, counts 454,648 new malicious open source packages discovered in the past year, bringing the total tracked since 2019 to 1.23 million, while annual downloads across the four largest registries reached 9.8 trillion. Log4Shell, patched since December 2021, was still downloaded 42 million times in 2025. The clerks note that the well is being poisoned faster than it is being drunk dry, and that a fix which nobody applies is indistinguishable, at a distance, from no fix at all.

October 2025: The dependency graph is the attack surface

The ENISA Threat Landscape 2025, published October 2025, records supply chain pathways among the fastest-growing classes of initial access against EU organisations, second only to stolen credentials, with state-aligned groups compromising managed services and shared infrastructure to reach targets they could not breach directly. What passes for faith, the threat landscape calls a pathway.

The state of the foundations

The founding exhibits remain Heartbleed, disclosed April 2014, and Log4Shell, disclosed December 2021: both in ubiquitous volunteer-maintained components, both still generating downloads and incidents years later. The economic model has not changed since; consumption is free, maintenance is donated, and the imbalance is now measured annually by the registries themselves. What has changed, since 2024 and 2025, is the institutional response: the CRA in force since December 2024, ENISA’s European Vulnerability Database live since May 2025, and supply chain failures ranked top of the OWASP Top 10 for 2025. Europe has begun regulating and cataloguing the problem. The volunteers, the clerks observe, are still unpaid.