We conducted an analysis of changes in risk assessment ratings over time and found that the risk rating changed in only minority of packages (7.4%). In these small number of cases the changes were primarily non-impactful, e.g. a package transitioning from medium risk to low risk, with changes primarily driven by fluctuation in download rates. These data helped inform our strategy for the risk assessment of existing packages - we re-assess the risk for major milestones like updates to the R version but for more incremental releases we carry over the risk assessment from the previous release.
0 commit comments