Open source software is widely used, with estimates suggesting that over 90% of codebases include it. Many organizations adopt open source software because it is free, but the community often notes that “open source is free as in puppies, not free as in beer.” This means while the software itself may be free, maintaining and customizing it requires significant effort and resources, such as engineering time and costs.
To better understand the costs associated with maintaining open source software, Google conducted a study focusing on the effort required to update open source packages within the company. The study aimed to answer two key questions: how long it takes for an engineer to update a package and whether complexity metrics could predict the relative effort needed for updates.
The findings revealed that most package updates at Google take four hours or less, but some can stretch into days or even months. Factors like local patches, customization, the number of package dependencies, and the number of upstream contributors were better predictors of update complexity than the age of the package or how many teams were using it internally.
The study acknowledged several limitations, including a bias towards the Go programming language and the exclusion of stale or archived packages. The research did not specify the tools used for updates, leaving the impact of any specific tool, including AI-enabled features, unexamined. Google encourages further investigation into the effects of different language ecosystems on maintenance efforts.