Who Holds the Name? Package authority, repository provenance and delisting in the official MCP Registry and in npm packages carrying MCP keywords — dataset v5 (2026-07-30 to 2026-09-02)
收藏资源简介:
v6 (freeze 2026-09-27). The window is extended from 2026-09-02 to 2026-09-27 (npm population from 2026-07-30, whole registry from 2026-08-23): 646 events on 588 names, 117 maintainer-set change points on 87 packages, a matched baseline of 85,163 audit intervals over 3,764 packages. Every analysis is rebuilt from scripts that ship in the deposit (build_01 … build_10), and verify_numbers_v6.py re-derives every number by a different code path. Rebuilding corrected v5.1 in four places and withdrew one reading; two of the corrections change a stated conclusion — the ±7-day leave-one-package-out instability of v5/v5.1 was an artefact of release lists taken from an earlier npm fetch than the baseline, and packages are not independent units: six scope-level changes hit several packages of one npm scope at once, and with each counted once the ±7-day excess is again not established. See README.md and ERRATA.md. v5.1 (2026-09-14). Corrects one number in v5: the netted maintainer additions across the seven snapshotted packages are 19, not 18. The summary had been computed on the window ending 2026-09-02 while the snapshot series runs to 09-07; the missed change is mohilsrivastava added to @heroku/mcp-server on 2026-09-03. Established by two independent recomputations (first-to-last snapshot diff; account-by-account netting of consecutive steps). No conclusion changes direction. The signed manifest, its Ed25519 signature and the three Bitcoin block proofs cover the crawl data files and are unchanged, and remain valid. See ERRATA.md.v5 of the dataset. The measurement window is unchanged (npm 2026-07-30 to 09-02, registry 2026-08-23 to 09-02); no new observations are added. Three things changed. (1) Table 2b, one change point per package (n = 40). The 52 change points sit on 40 packages, so the intervals in Table 2 treat correlated observations as independent draws. G. Bharti (arXiv:2608.00997) raised this and predicted the table would go uniformly null; it does the opposite, because the dependence is a selection effect rather than a variance one — of the 12 repeats the filter removes, 11 are silent and 5 come from one package. Result: 13 of 40 with a release in the interval (silent 67.5%, CI 52.0–79.9; rate ratio 1.61, CI 1.03–2.51), 21 of 40 at ±24 h (1.50, 1.12–2.02), 30 of 40 at ±7 d (1.27, 1.06–1.52). Taking the latest change point of each package instead of the earliest gives 12, 21 and 29, so the choice of representative does not carry the result. (2) The twelve suppressed repeats netted account by account against 30 daily maintainer snapshots of the seven packages that carry them: no step undoes the one before it, the window nets to 18 accounts added and 6 removed, and the pattern is an organisation onboarding or rotating publishers without cutting a release — a different event from a maintainer leaving without one. (3) Leave-one-package-out over all 40 packages: the silent share of Table 2 moves between 69.6% and 76.0% and the in-interval ratio between 1.19 and 1.50, but the ±7-day ratio does not survive — its lower bound falls between 0.99 and 1.07, and omitting either @mondaydotcomorg/atp-mcp-adapter or mcp-remote takes it below 1. Do not cite the ±7-day ratio as an established excess. Also: the OpenTimestamps proofs are now Bitcoin block proofs (blocks 965416 and 965419) rather than the calendar receipts shipped in v4 — same manifest, same digest, same signature, only the proof completed. Headline numbers are unchanged: 38 of 52 (73.1%, CI 59.7–83.2) maintainer-set changes had no npm-timestamped release inside their audit interval, against a matched baseline of 20.2% over 41,286 adjacent audit intervals of 2,811 packages. Preprint v8 and facts_v8.json replace v7. All scripts are standard-library; every headline number recounts from the deposited files.



