ZeroDrift M&A
REPORTE DE MUESTRASAMPLE REPORT

Este documento es la salida real del análisis pre-cierre de ZeroDrift M&A, corrido sobre un repositorio público. No es una maqueta: los números salen del historial de git del proyecto, procesado por el mismo motor que se usa sobre el target de un deal.

This document is the real output of the ZeroDrift M&A pre-close analysis, run against a public repository. It is not a mockup: every figure comes from the project's git history, processed by the same engine used on a deal target.

Sobre la anonimización. Los contribuyentes figuran acá como A, B, C. El entregable que recibe el cliente lleva nombres y correos completos — sin eso no se puede negociar retención ni redactar un período de transición. Esta versión va anonimizada porque el sujeto es un proyecto abierto cuyos mantenedores no son parte de ningún deal, no porque el análisis no los identifique.

On anonymisation. Contributors appear here as A, B, C. The client deliverable carries full names and email addresses — without them you cannot negotiate retention or draft a transition period. This version is anonymised because the subject is an open-source project whose maintainers are not party to any deal, not because the analysis fails to identify them.

Evaluación técnica pre-cierre

Pre-close technical assessment

Concentración de conocimiento y riesgo de continuidad

Knowledge concentration and continuity risk

RepositorioRepository
psf/requests
Commits
4.879
HistoriaHistory
2011-02-13 → 2026-07-09
GeneradoGenerated
2026-08-24
Corte de inactividadInactivity cut-off
2025-08-29
Datos leídosData read
Solo metadata de gitGit metadata only

Resumen para el comité

  • 57.7% de los cambios que sostienen el sistema los escribieron personas que ya no commitean.
  • El contribuyente principal concentra el 46.0% del total y su último commit es de 2019-09-23.
  • De 762 personas que tocaron el código en su historia, sólo 22 siguen activas.
  • 6 módulos vivos están concentrados por encima del 50% en alguien inactivo.
  • En el módulo de código del producto (src/requests) el autor principal aporta el 32.9% y su bus factor es 4.
Qué implica para la valuación

La transferencia de conocimiento no es una tarea post-cierre: es una condición del precio. El conocimiento ya salió de la organización y no hay a quién retener — lo que queda es documentar y reconstruir, y eso tiene un costo y un plazo que corresponde descontar de la valuación, no absorber después del cierre.

El esfuerzo se expresa en módulos y personas, no en moneda. Un comprador conoce su propia tarifa interna; convertir el hallazgo a dólares invitaría a discutir la tarifa en vez del hallazgo.

Leer esta muestra contra un target real

Este es un proyecto open source, y eso condiciona los números de dos maneras que conviene nombrar.

Primero, el recuento de contribuyentes está inflado por participación ocasional: la mayoría de esas 762 personas hizo uno o dos commits. Una empresa de software privada tiene un denominador de diez o veinte, y el mismo análisis se lee muy distinto.

Segundo —y esto empuja hacia el riesgo, no en contra—, un proyecto comunitario absorbe la salida de su autor principal porque hay una comunidad que la absorbe. Este proyecto perdió en 2019 a quien escribió el 46.0% de su historia y siguió funcionando. Una empresa con ocho ingenieros no tiene esa reserva: cuando la persona que sostiene un módulo se va, el conocimiento se va con ella.

Hallazgos

1El sistema lo escribió gente que ya no lo mantiene

AutorCommits ParticipaciónÚltimo commit Estado
Contributor A221446.0%2019-09-23Inactivo
Contributor B3296.8%2017-08-27Inactivo
Contributor C2334.8%2026-06-24Activo
Contributor D2244.7%2026-05-31Activo
Contributor E450.9%2013-01-17Inactivo
Contributor F420.9%2016-04-11Inactivo
Contributor G310.6%2015-06-29Inactivo
Contributor H280.6%2016-04-21Inactivo
Contributor I270.6%2012-03-08Inactivo
Contributor J240.5%2014-12-16Inactivo
Contributor K210.4%2013-11-06Inactivo
Contributor L180.4%2018-12-29Inactivo

2Concentración por módulo

El bus factor es cuántas personas hay que perder para quedarse sin la mitad del conocimiento de ese módulo. Un 1 significa que una sola persona lo sostiene.

La tabla va separada por tipo de módulo: mezclarlos hacía que documentación y plantillas de issues encabezaran el ranking de concentración y el código del producto quedara último, lo que se lee al revés de lo que el análisis dice. Al separarlo aparece un hallazgo que estaba tapado: los workflows de CI los sostiene una sola persona, y si nadie más sabe cómo se despliega, el equipo nuevo no puede publicar.

Código de producto

MóduloCommitsBus factorConcentraciónAutor principalEstado
(raíz)909247.9%Contributor AInactivo
src/requests2516432.9%Contributor AInactivo

CI y despliegue

MóduloCommitsBus factorConcentraciónAutor principalEstado
.github/ISSUE_TEMPLATE15173.3%Contributor AInactivo
.github/workflows70165.7%Contributor CActivo

Tests

MóduloCommitsBus factorConcentraciónAutor principalEstado
tests/certs42164.3%Contributor DActivo
tests/testserver33157.6%Contributor FInactivo
tests/test_lowlevel.py25244.0%Contributor CActivo
tests/test_testserver.py16237.5%Contributor CActivo
tests/test_utils.py70525.7%Contributor CActivo
tests/test_requests.py5371019.9%Contributor AInactivo

Documentación

MóduloCommitsBus factorConcentraciónAutor principalEstado
docs/index.rst187179.7%Contributor AInactivo
docs/dev48162.5%Contributor AInactivo
docs/conf.py40160.0%Contributor AInactivo
docs/_static16150.0%Contributor AInactivo
docs/community137333.6%Contributor AInactivo
docs/api.rst58332.8%Contributor AInactivo
docs/user4601221.5%Contributor AInactivo

3Origen del código

Sin el directorio técnico del target, el origen se infiere por dominio de correo. 86.5% de los commits no son atribuibles a ninguna organización: vienen de proveedores de correo gratuitos o de un dominio propio de la persona —el caso, muy frecuente entre desarrolladores, de quien registra un dominio con su nombre y lo usa como correo personal. Ese es el margen de ambigüedad de este análisis, y se declara en vez de disimularse.

Un dominio institucional con un solo commiteador sí atribuye: es esa institución aunque haya participado una persona. La tabla lista los principales dominios que atribuyen; no suma el total, porque el resto son dominios de un commit o dos. Con la planilla de nombres y correos del target todo esto pasa a ser nominal — y en un target corporativo la proporción de correos personales es mucho menor.

Dominio Commits Personas
cs.stanford.edu451
rackspace.com212
gilt.com171
sonymobile.com141
bloomberg.net121
zopatista.com121
twilio.com111
luc.edu101

4Radar de fin de soporte Riesgo alto

  • Python 3.10: fin de soporte el 2026-10-31, dentro de los próximos 18 meses

Manifiestos leídos: pyproject.toml, setup.py, requirements-dev.txt

Metodología y límites

Qué se leyó, exactamente

El repositorio se clonó con --bare --filter=blob:none: git trae el historial completo —autoría, fechas, qué archivo tocó cada commit— sin descargar el contenido de ningún archivo. El clon completo de este proyecto, con 4879 commits, ocupa 3,8 MB.

La única excepción son los manifiestos de dependencias, que el radar de fin de soporte necesita leer y que se listan arriba. Ningún otro archivo de código fuente fue descargado ni abierto.

Reproducilo

Cada cifra de este reporte deriva de datos públicos. El repositorio es psf/requests; el corte de historia es 2026-07-09 y el umbral de inactividad 2025-08-29.

git clone --bare --filter=blob:none https://github.com/psf/requests
python3 analizar.py --repo repo.git --salida datos.json --hoy 2026-08-24
python3 reporte.py  --datos datos.json --salida reporte.html

Alcance del análisis

  • Se excluyen los merges: no son trabajo de autoría, y contarlos le atribuye a quien mergea el trabajo de otro.
  • Se excluyen los bots (62 commits): contarlos como autores infla la dispersión y disimula la concentración real.
  • Se analizan sólo los archivos que existen hoy. Sin este filtro aparecían como riesgo módulos borrados hace más de una década: en un documento que se lee en una negociación, un falso positivo cuesta más que una omisión.
  • El historial de cada archivo se sigue a través de renombres. Este proyecto movió su código a otro directorio, y sin seguir renombres el archivo principal mostraba 18 commits en vez de 170.
  • Inactividad: sin commits en los últimos 12 meses (corte: 2025-08-29).
  • El impacto de dependencias completo —qué se rompe en cascada al cambiar un módulo— no forma parte del pre-cierre: requiere acceso al código y a la infraestructura, y se entrega en la modalidad post-cierre.

Este análisis mapea riesgo de continuidad operativa. No evalúa el desempeño individual de ninguna persona, y no debe usarse con ese fin.

Deliberadamente fuera de alcance

  • Seguridad y cumplimiento no se cubren: recomendamos un proveedor especializado.
  • Calidad interna del código no se evalúa, porque en esta modalidad el código fuente no se abre.
  • Costo de nube e infraestructura se ofrecen como trabajo post-cierre aparte.
Límites declarados de esta corrida
  • Identidad. El motor unifica automáticamente las identidades de git de una misma persona por correo y por nombre: en esta corrida detectó 41 casos, incluido el contribuyente principal, que commiteaba con cuatro correos distintos. La unificación por nombre no es infalible —dos personas homónimas se fusionarían— y con la planilla de nombres y correos del target pasa a ser exacta.
  • Origen. Un dominio se cuenta como organización sólo si lo usan dos personas o más. Un dominio de una sola persona es personal, no un proveedor: sin este criterio, el dominio propio del autor principal aparecía como dos proveedores externos.
  • Granularidad. src/requests concentra 2516 commits, más de la mitad del repositorio. Un bus factor calculado sobre un módulo de ese tamaño es un promedio, y puede tapar archivos individuales sostenidos por una sola persona. El análisis por archivo se entrega en la modalidad post-cierre.

Investment committee summary

  • 57.7% of the changes holding the system together were written by people who no longer commit.
  • The top contributor accounts for 46.0% of all work; their last commit dates to 2019-09-23.
  • Of 762 people who ever touched the code, only 22 remain active.
  • 6 live modules are over 50% concentrated in someone inactive.
  • In the product's source module (src/requests) the primary author contributes 32.9%, with a bus factor of 4.
What this means for valuation

Knowledge transfer is not a post-close task here: it is a pricing condition. The knowledge has already left the organisation and there is no one to retain — what remains is documenting and rebuilding, which carries a cost and a timeline that belongs in the valuation, not in the post-close budget.

Effort is expressed here in modules and people, not in currency. An acquirer knows its own internal rate; converting the finding to a dollar figure would invite an argument about the rate instead of about the finding.

Reading this sample against a real target

This is an open-source project, and that shapes the numbers in two ways worth naming.

First, the contributor count is inflated by drive-by participation: most of those 762 people made one or two commits. A privately held software company will have a denominator of ten or twenty, and the same analysis will read very differently.

Second — and this cuts toward the risk rather than away from it — a community project absorbs the departure of its principal author because there is a community to absorb it. This project lost the contributor behind 46.0% of its history in 2019 and continued to function. A private company with eight engineers has no such reservoir. When the person holding a module leaves, the knowledge leaves with them.

Findings

1The system was written by people who no longer maintain it

AuthorCommits ShareLast commit Status
Contributor A221446.0%2019-09-23Inactive
Contributor B3296.8%2017-08-27Inactive
Contributor C2334.8%2026-06-24Active
Contributor D2244.7%2026-05-31Active
Contributor E450.9%2013-01-17Inactive
Contributor F420.9%2016-04-11Inactive
Contributor G310.6%2015-06-29Inactive
Contributor H280.6%2016-04-21Inactive
Contributor I270.6%2012-03-08Inactive
Contributor J240.5%2014-12-16Inactive
Contributor K210.4%2013-11-06Inactive
Contributor L180.4%2018-12-29Inactive

2Concentration by module

Bus factor is how many people you would have to lose to lose half the knowledge of that module. A 1 means a single person holds it.

The table is split by module type: mixing them put documentation and issue templates at the top of the concentration ranking and left the product code last, which reads the opposite of what the analysis says. Splitting it surfaces a finding that was hidden: CI workflows are held by a single person — and if no one else knows how deployment works, the new team cannot ship.

Product code

ModuleCommitsBus factorConcentrationPrimary authorStatus
(root)909247.9%Contributor AInactive
src/requests2516432.9%Contributor AInactive

CI and deployment

ModuleCommitsBus factorConcentrationPrimary authorStatus
.github/ISSUE_TEMPLATE15173.3%Contributor AInactive
.github/workflows70165.7%Contributor CActive

Tests

ModuleCommitsBus factorConcentrationPrimary authorStatus
tests/certs42164.3%Contributor DActive
tests/testserver33157.6%Contributor FInactive
tests/test_lowlevel.py25244.0%Contributor CActive
tests/test_testserver.py16237.5%Contributor CActive
tests/test_utils.py70525.7%Contributor CActive
tests/test_requests.py5371019.9%Contributor AInactive

Documentation

ModuleCommitsBus factorConcentrationPrimary authorStatus
docs/index.rst187179.7%Contributor AInactive
docs/dev48162.5%Contributor AInactive
docs/conf.py40160.0%Contributor AInactive
docs/_static16150.0%Contributor AInactive
docs/community137333.6%Contributor AInactive
docs/api.rst58332.8%Contributor AInactive
docs/user4601221.5%Contributor AInactive

3Code origin

Without the target's technical directory, origin is inferred from email domain. 86.5% of commits cannot be attributed to any organisation: they come from free email providers, or from a person's own domain — the common developer practice of registering a domain in one's own name and using it as a personal address. That is this analysis's ambiguity margin, stated rather than hidden.

An institutional domain with a single committer does attribute: it is that institution even if only one person took part. The table lists the main attributing domains; it does not sum to the total, because the remainder are domains with one or two commits. With a name-and-email roster from the target this becomes nominal — and on a corporate target the share of personal addresses is far lower.

Domain Commits People
cs.stanford.edu451
rackspace.com212
gilt.com171
sonymobile.com141
bloomberg.net121
zopatista.com121
twilio.com111
luc.edu101

4End-of-support radar High risk

  • Python 3.10: end of support on 2026-10-31, within the next 18 months

Manifests read: pyproject.toml, setup.py, requirements-dev.txt

Methodology and limits

What was read, exactly

The repository was cloned with --bare --filter=blob:none: git fetches the full history —authorship, dates, which file each commit touched— without downloading the contents of any file. The complete clone of this project, with 4879 commits, takes 3.8 MB.

The only exception are the dependency manifests, which the end-of-support radar must read and which are listed above. No other source file was downloaded or opened.

Reproduce it

Every figure in this report derives from public data. The repository is psf/requests; the history cut-off is 2026-07-09 and the inactivity threshold is 2025-08-29.

git clone --bare --filter=blob:none https://github.com/psf/requests
python3 analizar.py --repo repo.git --salida datos.json --hoy 2026-08-24
python3 reporte.py  --datos datos.json --salida reporte.html

Scope of the analysis

  • Merges are excluded: they are not authorship, and counting them credits the merger with someone else's work.
  • Bots are excluded (62 commits): counting them as authors inflates dispersion and masks real concentration.
  • Only files that exist today are analysed. Without this filter, modules deleted over a decade ago showed up as risk: in a document read during a negotiation, a false positive costs more than an omission.
  • Each file's history is followed across renames. This project moved its code to a different directory; without rename tracking the main source file showed 18 commits instead of 170.
  • Inactivity: no commits in the last 12 months (cut-off: 2025-08-29).
  • Full dependency impact —what breaks downstream when a module changes— is not part of the pre-close scope: it requires code and infrastructure access, and is delivered in the post-close engagement.

This analysis maps operational continuity risk. It does not assess any individual's performance and must not be used for that.

Deliberately out of scope

  • Security and compliance posture is not covered — we recommend a specialist provider.
  • Internal code quality is not assessed, because source code is not opened in this modality.
  • Cloud cost and infrastructure analysis are available as a separate post-close engagement.
Declared limits of this run
  • Identity. The engine automatically merges a person's multiple git identities by email and by name: this run detected 41 cases, including the top contributor, who committed under four different addresses. Name-based merging is not infallible — two people sharing a name would be merged — and becomes exact with the target's name-and-email roster.
  • Origin. A domain counts as an organisation only if two or more people use it. A single-person domain is personal, not a vendor: without this rule, the top author's own domain showed up as two external vendors.
  • Granularity. src/requests holds 2516 commits, over half the repository. A bus factor computed over a module that size is an average and can mask individual files held by one person. Per-file analysis is delivered in the post-close engagement.

¿Querés esto sobre tu propio repositorio?

Want this run on your own repository?

Veinte minutos. Te muestro el análisis corriendo sobre datos tuyos.

Twenty minutes. I'll show you the analysis running on your own data.

Agendar una llamadaSchedule a call O escribinos aOr email contact@canonplatform.com