GitDealFlowsignals
3 / 30

Week 1, Learn · Day 3 of 30

Day 3: Dependents graph

The hidden GitHub page, cheapest external-adoption proxy.

Day 3 in one paragraph: Most investors don't know GitHub exposes dependents. The dependents graph shows you every public repo that depends on this startup's code, the cheapest proxy for 'is anyone actually using this'. You will spend about five minutes, end with a concrete artifact, and the whole curriculum stays free at this URL permanently.

Where this day sits in the 30

Week 1 teaches the six atomic signals one at a time, each on the org you picked on day one. Day 3 of 30 sits 10% of the way through, in week 1, learn, one of four one-week phases. This day also carries a bonus exercise for anyone with extra time. Everything in this challenge is built from public GitHub signals, the same data that powers the weekly deal-flow feed, and the day's lesson is worth roughly €89 in equivalent consulting time by the anchoring we use across the curriculum.

Yesterday

Yesterday's contributor-diversity reading told you whether the team is real. Today's signal tells you whether anyone outside the team cares about what they're building.

Why this signal matters

Most investors don't know GitHub exposes dependents. The dependents graph shows you every public repo that depends on this startup's code, the cheapest proxy for 'is anyone actually using this'.

The 5-minute exercise

  1. 1Open the org's flagship repo (the one in their README, or the most-starred).
  2. 2Click Insights → Dependency graph → Dependents.
  3. 3If the page exists: count the dependents, look at the names.
  4. 4If the page is empty or missing: the package is private or pre-distribution. Note that.

What you’re filtering for

Dependents that are not the startup's own repos. Real external usage means real adoption. A few hundred external dependents on a developer-tools startup is a strong product-market-fit signal even if revenue is zero.

Edge case

Some orgs use private package registries (npm scoped, internal PyPI). Dependents won't show, that's a sign of enterprise distribution, not weakness. Cross-check with npm-stat.com or pypistats.org if a public package exists.

Bonus

Cross-reference the dependents list against your portfolio's GitHub orgs. If two of your portfolio companies are already using this startup's code, that's a warm-intro vector your AngelList syndicate doesn't have.

Tomorrow

Tomorrow: README freshness, the most under-rated leading indicator on this list.

Common questions about day 3

How long does day 3 take?
About five minutes of hands-on work against the org you picked on day one. The reading adds another two or three. If you are short on time the exercise alone still delivers the day's point.
Do I need any tools or paid data for dependents graph?
No. Every exercise in the challenge runs on public GitHub data and a browser. The feed that automates the same checks is available, but the curriculum itself is deliberately tool-free so the habit lands before the tooling.
What if I miss a day?
Every day is permanent at its own URL, so you can pick up exactly where you stopped. The sequence matters, each day builds on the previous one's artifact, but the pace is yours. Many people run the 30 days across six or seven weeks instead of four.

Curriculum: /challenge · Methodology: /methodology · Paper: ssrn.com/abstract=6606558

🚀 Explore Our Network

21-47 days
Signal Lead Time (median 31d)
$80M+
Rounds Tracked
90 sec
Per Scan
5,000+
Founders Tracked

One missed signal is a missed round. Get the Velocity Verdict in your inbox every Sunday free.

Get Free Signals

Free weekly digest. Cancel anytime. No spam, no VC pitches just data.