Depsly Research

Original research on dependency governance, structural risk, and reviewability

Research findings from 100 JavaScript and TypeScript repositories

State of Dependency Governance 2026

Most organizations do not just have a vulnerability problem. They have a dependency governance problem. This report benchmarks dependency depth, transitive complexity, concentration hotspots, and review readiness across 100 real projects.

Preview a few sample pages first, or unlock the full report on the right.

100

Repositories analyzed

83%

Crossed the deep-graph threshold

41%

Showed a concentration hotspot

94%

Produced nontrivial review work

Unlock the report

Preview findings

Why dependency governance deserves its own lens

Vulnerability lists do not explain how reviewable, traceable, or governable a dependency graph really is. This report focuses on the structural signals that shape real review work.

Finding 1

The median repository contained 1570.5 dependency nodes.

Finding 2

Transitive complexity dominated the median repository, with a median transitive ratio of 0.7071.

Finding 3

A small set of high-influence packages repeatedly shaped graph exposure across unrelated projects.

Finding 4

Dependency governance is often a workflow problem, not just a vulnerability-list problem.

Who it’s for

Built for teams responsible for dependency oversight

Compliance / GRC

Use the report to understand what dependency governance evidence and repeatability should look like in practice.

Security / AppSec

Use the report to understand where transitive complexity and graph concentration create review friction.

Engineering leadership

Use the report to understand dependency debt, structural complexity, and why governance cannot be reduced to direct dependencies alone.