logo

2025 State of Code Security: Key Trends and Risks

ID: 3bb8a045-20b9-55b2-ba71-aa88a10067e9

STIX ID: report--3bb8a045-20b9-55b2-ba71-aa88a10067e9

Feed Name: Wiz Blog

Date Published: 2025-02-20

Date Updated: 2026-05-01

...
...

The 2025 State of Code Security Report by Wiz Threat Research analyzes hundreds of thousands of repositories and CI/CD pipelines across GitHub, GitLab, and Azure DevOps, revealing widespread risks: **35%** of GitHub repos are public, **61%** of organizations have public repos exposing cloud secrets, many enterprises run non‑ephemeral self-hosted runners with **3×** more packages and High/Critical vulnerabilities, and over‑permissive GitHub Apps frequently grant write access via the widely used *pull_requests* and *contents* scopes. The report urges stronger repo governance, robust secrets management, hardening/ephemeralization of CI/CD runners, and least‑privilege third‑party app scopes to reduce lateral movement and code tampering risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.