logo

Firms are embracing Open Source. Securing it? Not so much.

ID: 915388b0-0398-53dc-883a-683e8c3ca6db

STIX ID: report--915388b0-0398-53dc-883a-683e8c3ca6db

Feed Name: Security Ledger

Date Published: 2020-05-20

Date Updated: 2026-04-26

Author: Jack Monahan

...
...

Synopsys' 2020 OSSRA found open-source software in 99% of audited codebases, comprising about 70% of code; 75% of codebases contained at least one public vulnerability and roughly half contained high-risk vulnerabilities, averaging 82 vulnerabilities per codebase. The report highlights growth in open-source use, concentrated reuse of common components with known issues, and recommends building a software Bill of Materials (BOM), continuous monitoring, and not relying on a single vulnerability source to manage open-source security risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.