Research

Every claim made on this site is backed by something. This section publishes the work.

It is deliberately unglamorous: counts pulled from public APIs, a maintenance record anyone can reproduce, and a list of decisions with the reasoning shown — including the ones that are still open.

A note on names. This research was assembled partly from public data and partly from private conversations with organizations and individuals who depend on this format. Those references have been removed. Nobody gets volunteered into a public position they did not take. People and organizations who want to identify themselves are welcome to do so in the discussion — on their own terms, in their own words.

What remains is the evidence, stated in categories rather than names. If you would rather be counted privately than post in public, email me directly — it counts the same, and nothing is attributed without your say-so.


The maintenance record

What the repository and the wider organization actually look like — issues closed per year, the open backlog, release cadence, what recent commits consist of, and the state of the surrounding tools. All of it reproducible from public data.

Read →
Who depends on this

The dependent base, by category — governments, enterprises, vendors, tooling. Plus the pattern that matters most: what the ecosystem built, and what it conspicuously did not.

Read →
The plan, and what is open

The decisions taken so far and the reasoning behind each, the questions deliberately left open, and the risks worth naming out loud.

Read →

Method

Maintenance data was pulled from the GitHub API on 2026-07-29 — the full issue and pull request history of the linter’s repository (2,789 records), the repository list for its organization (125 public repositories), release history, and commit history. Anyone can re-run it and should; these numbers will drift.

Dependency data was assembled from the npm registry (packages depending on the engine, plus keyword searches), GitHub repository search, and the upstream project’s own community index of rulesets in the wild — which was itself last updated eighteen months ago and undercounts significantly.

Everything else — the parts that came from conversations with people who run this in production — informs the reasoning but is not reproduced here. Where a claim rests only on a private conversation, it is either omitted or stated generically enough that no one is identified.


Found an error, or have data that contradicts this? That is genuinely useful.

Say so in the discussion → Or email privately →