lastseen.deva dated register of software-component continuity

lastseen.dev

An independent temporal notary for software components and agent infrastructure. We record what the public record showed — and the date we saw it. Dated, append-only, hash-chained. A series no one can recreate after the fact. Not even us.

Paste a repo, an org, or a package.json. We'll tell you which of your dependencies stopped being maintained — and when we last checked.

no login · no account · free

the time dimension

Ask about any date. Every read endpoint accepts ?as_of=YYYY-MM-DD and answers with the observation's actual date, its source, and a censoring status — never a nearest-value guess. A date before our coverage returns not-observed-at-date. A carried-forward value is marked interval-censored: we show when we last saw it, not an invented in-between.

The proof. Every dated observation is sealed into a daily SHA-256 hash chain. Today's chain head is public at /api/chain/head; the recipe to recompute it yourself — machine or human — is at /verify. Each Zenodo release of our datasets carries the then-current chain head: an external, timestamped anchor that cannot be backdated by anyone. Including us.

coverage

616,196 components watched. The daily observation series began 2026-07-29 and grows every day.

MCP servers28,824the full MCP census (2026)npm packages532,037observed · npm is an open registry, no fixed totalGitHub Actions32,846dated observations · 223,387 of 33,527 classifiable from ingested enumeration (ecosyste.ms, 2026-09-14)Docker images22,489endoflife.date product-cycles · Docker Hub has no fixed totallast checked2026-09-17

Known gap: there was no full re-probe on 2026-07-30, so any change of state on that date is bounded to the observations either side of it, not dated to the day itself.

registers

Browse the dated MCP register: 9,638 not-maintained entities (deleted, abandoned, or dormant) across 7,992 owners, observed of the 28,824-entity MCP census. Latest observation 2026-09-17.

Browse the dated npm register: 4,359 not-maintained packages (each with at least 25 npm dependents), observed 2026-08-03.

Browse the dated GitHub Actions register: 2,835 not-maintained actions (each with at least 10 stars), observed 2026-08-03.

Browse the dated Docker base-image register: 403 end-of-life cycles across 25 images, observed 2026-08-03.

methodology

Every reported state is a dated read of the component's public record. The maintenance state is derived from the last public commit on the default branch:

staterule
alivelast commit ≤ 180 days ago
dormantlast commit 180–365 days ago
abandonedlast commit > 365 days ago
archivedthe repository's own archived flag is set
deletedan authoritative HTTP 404
not_observed403 / 429 / timeout / network error — recorded as not-checked

A subject we have not observed is recorded as not-checked — never as gone. Absence of a record is absence of a record, nothing more.

Interval censoring. We assert only the dated reads we actually took. Between two observations we do not guess a state; a gap stays a gap. When a change happens inside an unobserved span, we date it to that span, not to a single day.

What we read. The daily series is a dated read of the public GitHub record; the MCP population was seeded from a public census and re-read the same way. Each row keeps its own source and method. Observations are collected by the Nerq crawl infrastructure.

We publish dated observations, not a composite score and not a prediction.

Verify the supply chain. The lastseen.dev CI Action signs every release with Sigstore — build provenance and an SPDX SBOM, both recorded in the public Rekor transparency log — and pins every action in its own workflows to a full commit SHA, never a mutable tag. Verify a downloaded release with gh attestation verify <file> --owner agentidx. This register can be independently verified, not merely asserted.

what we don't do

We do not rank, recommend, name alternatives, or advise about any named party. We sell no score and no prediction. We publish dated observations and a public correction log. What drove usage stays free forever; charges only ever apply to new capabilities, with 12 months' notice per /terms.

about

A free, independent service. No company sits behind it, and no account is required to see results or to use the API under the free limit. You can optionally register to be notified about the components you watch — that processes only your email and organisation, nothing more (privacy). Contact: [email protected]. Operational status.

cite

The dataset dump is archived on Zenodo under a permanent Concept DOI that always resolves to the latest version. Cite as:

lastseen.dev (2026). Nerq MCP-server repository mortality. Zenodo. https://doi.org/10.5281/zenodo.21869879

Data licensed CC-BY-4.0; each per-release snapshot also carries its own version DOI.

dispute an observation

To contest an observation, send the component identifier (owner/repo or a package coordinate) and the state you assert, with a public URL showing the current HTTP status and last-commit date, to [email protected]. We re-read the public source and, if it differs, issue a dated correction, shown on the component's page. Target response: 5 business days. Full process: dispute.