Skip to content

Latest commit

 

History

18 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

conemass

DOI

Rank a dependency graph by concentration of reach: which packages sit inside the most toolchains, weighted by how concentrated each toolchain's trust is. One file, no dependencies, any graph, seconds.

node conemass.mjs Cargo.lock --top 50

The metric's whole argument fits in one command. Run it on the eight-package lockfile in this repo:

node conemass.mjs test-cargo.lock
conemass_rank,name,conemass,direct_dependents,dependents_rank
1,unicode-ident,2.4262,2,2
2,proc-macro2,1.4262,3,1
3,quote,0.9262,2,2
4,syn,0.5929,1,4
5,serde_derive,0.3429,1,4
6,serde,0.1429,1,4
6,tokio,0.1429,1,4
8,myapp,0.0000,0,8

unicode-ident comes out first with two direct dependents, above proc-macro2 with three. Counting dependents says proc-macro2 matters more; counting toolchains that terminate in you says unicode-ident is the floor everything else stands on. You can verify this by hand on eight packages — and it is exactly what happens at registry scale, where unicode-ident ranks #2 of 84,439 crates against #3,304 by dependent count.

Why this metric

The rankings that guide security attention mostly count activity and popularity. Those miss a specific profile: the quiet, finished, deeply embedded library — few direct dependents, present in nearly every build. The OpenSSF criticality-score top-1000 contains Kubernetes and misses zlib. On the last Debian release before the xz backdoor, conemass ranked liblzma5 #8 of 63,436 packages (against #173 by dependent count) — twenty-one months before anyone knew to look.

The metric:

conemass(x) = sum over packages u whose truncated dependency cone
              contains x of 1 / |cone(u)|

Count every toolchain you are part of, weighting each by the reciprocal of its size. High conemass with a low dependent count is the quiet load-bearing profile. The rows that matter for triage are the ones where conemass_rank is far ahead of dependents_rank.

Usage

node conemass.mjs <input> [--cap N] [--top N] [--out FILE]

Inputs (auto-detected):

  • Cargo.lock — parsed directly. Both dependency entry forms resolve ("serde" and "serde 1.0.188"). Versions are collapsed to package names: a crate present at two versions is one node whose dependency set is the union, consistent with the package-level published rankings.
  • edge-list text — one dependent,dependency pair per line (comma, tab, or space separated; a first line containing "depend" is skipped as a header).
  • .json{"nodes":[names...],"edges":[[depIdx,depIdx]...]} with edges as [dependent, dependency] index pairs, or a plain JSON array of [dependent, dependency] name pairs.

Flags: --cap N cone truncation (default 200; rankings are insensitive to cap 50–800 on tested corpora). --top N emit only the top N rows. --out F write CSV to a file instead of stdout.

Output columns: conemass_rank, name, conemass, direct_dependents, dependents_rank.

Guarantees and caveats

  • Deterministic. The same graph produces byte-identical output regardless of input file ordering (traversal and float-accumulation order are canonicalized by package name; verified on a shuffled 63k-node corpus).
  • Cycles handled via SCC condensation; members of a dependency cycle share a score.
  • Ties take the minimum rank.
  • A 100k-node registry takes seconds; string edge keys keep dedup correct past the ~2M-node limit where numeric packing would silently collide.
  • Descriptive rankings, not certified claims. conemass's head is deliberately library-heavy — libraries are the attack surface.

Published rankings

rankings/ contains dated top-1000 CSVs, generated with this tool:

file corpus snapshot
rankings/debian-trixie-2025-top1000.csv Debian main/binary-amd64 (68,750 packages) trixie, 2025
rankings/crates-2022-top1000.csv crates.io (84,439 crates) 2022

Computed 2026-09-02 and published as-is: every future incident either involves a package in these files or it does not, and the files are dated. (2026-09-05: the CSV header row was renamed oracle_*conemass_*; every data row is unchanged from the 2026-09-02 computation, as the git history shows.)

Background

The validation — the xz retrodiction, the crates.io replication, the comparison against the OpenSSF criticality-score top-1000, and a registered RustSec retrodiction reported in full including the loss — is written up in the quiet-criticality paper, included in this repo (PDF).

Provenance and priority

The metric (harmonic cone-membership mass, "concentration of reach") was derived and registered — under its working name ORACLE, which the frozen study records retain — on 2026-09-01 as the complete mechanism of a synthetic growth effect (thefalsework/papers, accretion-study/05-oracle.mjs, with the derivation in accretion-study/THEORY.md). It was repurposed as a supply-chain criticality signal and published on 2026-09-02 with this tool, the dated Debian and crates.io rankings in rankings/, the xz retrodiction (liblzma5 #8 of 63,436 on pre-disclosure Debian), and the write-up above — including a registered retrodiction against RustSec advisories that the metric lost at the pooled cell, reported in the paper's limitations. Full commit history in both repositories; this repository is also archived at Software Heritage and on Zenodo (DOI: 10.5281/zenodo.22261985, with the dated ranking CSVs attached to the corresponding GitHub release). Later work using concentration-of-reach ranking of dependency graphs should cite this record (CITATION.cff).

License

Apache-2.0.

About

Rank a dependency graph by concentration of reach. One file, no dependencies. Ranked liblzma5 #8 in Debian 21 months before the xz backdoor was found.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages