More than 180 million developers now build on GitHub, up 23% year-over-year, according to GitHub’s Octoverse 2025 report published in October 2025. That growth is not slowing down: over 36 million of those developers joined in the past year alone, and the platform now hosts 630 million repositories. The open source code those developers ship is also spreading faster into commercial software than ever, which is where the story gets more complicated for anyone shipping a product built on it.

How many developers actually use GitHub in 2026?

180 million developers now build on GitHub as of October 2025 180M developers now buildon GitHub

GitHub’s own Octoverse 2025 report puts the platform’s total developer count at more than 180 million as of October 2025, up 23% from the year before. On average, that works out to roughly one new developer joining GitHub every second across 2025, adding up to more than 36 million new accounts over twelve months. The pace has been consistent for years: GitHub passed 100 million total developers in early 2023, which means the platform has grown by roughly 80% in under three years.

GitHub Total Developers, 2023 vs. 2025 050100150200M100Early 2023180October 2025

Figure 1: Total developers on GitHub, two verified snapshots roughly 33 months apart. Source: GitHub Octoverse reports, 2023 baseline and Octoverse 2025.

That growth rate matters for anyone tracking how much software now depends on code written outside a single company’s walls, since every one of those 180 million developers is a potential source of a dependency someone else’s product will eventually ship.

How much code got pushed and shared in 2025?

Developers pushed nearly 1 billion commits in 2025, precisely 986 million, a 25.1% increase over 2024, according to GitHub’s Octoverse workflow data. Zoomed out further, GitHub counted 1.128 billion total contributions to public and open source repositories across the year, spread across a platform that now holds 630 million repositories in total, 121 million of which were created in 2025 alone.

GitHub Repositories by Type, 630 Million Total (Oct 2025) 395M235MPublic repositories395MPrivate repositories235M

Figure 2: Repository count in millions, public versus private, out of 630 million total repositories. Source: GitHub Octoverse 2025.

Private repository growth actually outpaced public growth in 2025, up 33% year-over-year against 19% for public repos, which tracks with more companies building proprietary products on top of open source foundations rather than publishing everything in the open.

Which language is driving the open source surge?

TypeScript overtook both Python and JavaScript in August 2025 to become GitHub’s most-used language, according to Octoverse 2025. TypeScript added 1.05 million contributors year-over-year, a 66.63% increase, a growth rate nearly three times the platform’s overall 23% developer growth. GitHub’s own analysis ties the jump partly to AI-assisted coding tools favoring typed languages, alongside a broader shift toward AI development: the platform now counts 4.3 million AI-related repositories, and 1.1 million public repositories use an LLM SDK directly, up 178% year-over-year.

Software licensing terms rarely track language choice, but a language surge this fast means a large wave of new dependencies, and new dependencies are exactly where open source licensing risk tends to enter a codebase unnoticed.

How much open source code hides inside commercial software?

Almost all of it, and the share keeps climbing. Black Duck’s 2026 Open Source Security and Risk Analysis (OSSRA) report, based on 947 audited codebases spanning 17 industries and covering the period from November 2024 through October 2025, found that 98% of commercial codebases now contain open source components. The average application runs 1,180 distinct open source components, up from 911 the year before, a 29.5% increase in a single year.

Share of commercial codebases with each open source license issue, 2025 Unresolved license conflicts68Custom or modified license11No detected license at all8

Figure 3: Share of commercial codebases carrying each type of open source license issue, 2025. Source: Black Duck, 2026 OSSRA Report.

Black Duck sells software composition analysis and open source risk management tools, so it has a commercial interest in reporting elevated risk figures; its sample size and methodology are disclosed, but no fully independent, non-vendor audit of comparable scale currently exists to cross-check these exact percentages. Treat the compliance figures below as the best available industry benchmark rather than an independently replicated finding.

How many open source components carry license risk?

68% of commercial codebases scanned in 2025 had at least one unresolved open source license conflict, up from 56% a year earlier, according to Black Duck’s 2026 OSSRA report, the largest year-over-year jump the report has recorded in nine years of publication. Separately, 8% of scanned codebases contained at least one component with no detected license at all, and 11% carried a custom or modified license that requires individual legal review rather than a standard permissive or copyleft template.

License issueShare of codebases affected
Unresolved license conflicts68%
Custom or modified license11%
No detected license at all8%

Source: Black Duck, 2026 OSSRA Report, 947 codebases audited.

Most engineering teams assume that if a dependency compiles and passes its tests, its license terms are someone else’s problem. The audit data says otherwise: a license conflict does not block a build, it just sits there until a customer, an acquirer, or a court asks about it. For how rarely the underlying legal text actually gets read once it does surface, see our EULA reading-behavior data, which found that only about 9% of consumers read a license agreement at all before accepting it.

What should a business actually do about open source license compliance?

Figure 4: A minimum compliance test for a new open source dependency, synthesized from Black Duck’s 2026 OSSRA findings above.

A component that fails that first test does not automatically become unusable, but it does need someone to make an active decision about it rather than let it ship by default. That decision eventually needs to be reflected in the license terms a business presents to its own users and customers, not just an internal spreadsheet of dependency licenses. A EULA Generator that accounts for the bundle of third-party open source terms underneath a product gives a business a single, current agreement to point to instead of relying on whatever the original open source licenses happened to say on their own.

For the wider enterprise licensing and audit picture beyond open source specifically, including how often companies get audited and by whom, see our software licensing audit and market data. Enterprise software spend and per-seat licensing costs are a related, fast-growing story in their own right, though a dedicated breakdown of that spend is not yet published on this site.

How outdated are the open source components most apps run?

Old, and getting older relative to what is available. Black Duck’s 2026 OSSRA report found that 93% of scanned codebases contained at least one component with no development activity in the past two years, and 92% contained components more than four years out of date. Only 7% of components in the average codebase run the latest available version, and 41% are ten or more versions behind the current release.

Open Source Component Freshness in Commercial Codebases (2026 OSSRA) No dev activity 2+ years93%4+ years out of date92%10+ versions behind41%Running latest version7%

Figure 5: Share of audited codebases affected by each freshness problem. Source: Black Duck, 2026 OSSRA Report.

Stale components compound the license risk above, since a component with no active maintainer is also one nobody is going to fix or clarify licensing terms for. Black Duck’s report also found the mean number of known vulnerabilities per codebase more than doubled year-over-year, from 280 to 581, a pattern that tracks closely with how many components go untouched for years at a time.

How does open source growth compare to open source risk, side by side?

Figure 6: Three dated milestones spanning open source platform growth and open source legal risk. Sources: GitHub Octoverse reports, 2023 and 2025; Black Duck, 2026 OSSRA Report.

MetricEarlier baselineLatest measurementChange
Total developers on GitHub100M (early 2023)180M (Oct 2025)+80%
Avg. open source components per app9111,180+29.5%
Commercial codebases with license conflicts56%68%+12 pts
Mean known vulnerabilities per codebase280581+107%

Sources: GitHub Octoverse 2025; Black Duck, 2026 OSSRA Report.

Growth and risk are climbing together, not trading off against each other. More developers and more repositories mean more open source code shipping into commercial products, and the compliance data has not caught up with that pace at all.

The Bottom Line

Open source usage is not slowing down: GitHub crossed 180 million developers in 2025, up 23% year-over-year, and commercial applications now average 1,180 open source components each, up nearly 30% in a single year. What has not kept pace is compliance. 68% of commercial codebases carry an unresolved license conflict, the sharpest jump in nine years of OSSRA reporting, and more than nine in ten scanned codebases run components that are years out of date. That gap between how fast open source usage grows and how slowly license hygiene improves is where legal exposure quietly builds up inside a product nobody thought to audit until an acquirer, a customer, or a court asked to see the paperwork.

Frequently Asked Questions

How many developers are on GitHub in 2026? More than 180 million developers now build on GitHub, up 23% year-over-year, with more than 36 million new developers joining in the past year, according to GitHub’s Octoverse 2025 report published in October 2025.

How many open source components does the average commercial application use? The average commercial application contains 1,180 open source components, up from 911 the year before, according to Black Duck’s 2026 Open Source Security and Risk Analysis (OSSRA) report, which scanned 947 codebases across 17 industries.

What percentage of commercial software has open source license conflicts? 68% of commercial codebases scanned in 2025 had at least one unresolved open source license conflict, up from 56% a year earlier, the largest year-over-year jump in the OSSRA report’s history, per Black Duck’s 2026 report.

Which programming language is growing fastest on GitHub? TypeScript overtook both Python and JavaScript in August 2025 to become GitHub’s most-used language, gaining 1.05 million contributors year-over-year, a 66.63% increase, according to GitHub’s Octoverse 2025 report.

Sources and References

  1. GitHub. “Octoverse 2025: A new developer joins GitHub every second as AI leads TypeScript to #1.” Published October 2025.
  2. GitHub. “What 986 million code pushes say about the developer workflow in 2025.” Octoverse 2025 series.
  3. GitHub. “Octoverse 2024.” Source for the 100 million total developers milestone reached in early 2023.
  4. Black Duck. “2026 Open Source Security and Risk Analysis (OSSRA) Report.” Published March 2026, covering 947 codebases audited November 2024 through October 2025.

Note: All figures verified as of September 2026. GitHub’s Octoverse figures reflect a snapshot as of October 2025; Black Duck’s OSSRA figures reflect audits conducted through October 2025 and published March 2026. Open source usage and license-compliance figures are refreshed at least twice a year.