Adoption & Community Savings
Most projects show you raw download counts and hope you don't ask questions. We ask them for you: downloads are bot-filtered, savings come from an opt-in census that starts at zero and can't be inflated, and every number below is computed by public code from a public git branch.
connecting to the metrics branch…
The number everyone shows vs. the one that's true
A public PyPI package receives constant traffic from supply-chain scanners (Snyk/Socket-class), package-intel crawlers (deps.dev, libraries.io), and malware sandboxes — every new release triggers fleet-wide sweeps. They report no operating system; pip on a real machine does. Even the filtered number counts events (CI reinstalls, upgrades), not people — provable people are the census tile. So we split:
Who actually runs it — and what it saves them
Machines that consented (distil census on). Anonymous install ids, schema frozen by test, fully disclosed — preview your own payload anytime with distil census show.
Two paths, three validation layers, one public datastore
Passive registry stats involve zero code on anyone's machine. The census is validated at the worker, re-validated in CI, and capped again at rollup — then stored in a git branch anyone can read.
Freshness · census re-rolls within ~1 min of any ping · registry stats nightly (PyPI publishes daily) · badges re-poll every 5 min · this page fetches on load
DO_NOT_TRACK=1 wins over everything — see TELEMETRY.md.