High Risk of Open-Source Software Components Detected in New Report

Date:

A recent report by Lineaje, a software supply chain security company, has found that 82% of open-source software components are inherently risky due to vulnerabilities, security issues, code quality or maintainability issues. This means that even though more than 70% of the software used by organizations is open-source, these components often lack tracking, maintenance, updates, and inventory, leaving them prone to exploitation. This news comes shortly after a warning from CISA (Cybersecurity and Infrastructure Security Agency) to software companies to follow secure-by-design processes and ship secure software.

Lineaje also investigated a set of top 44 popular projects from the Apache Software Foundation and found that 68% of the dependencies were from third-party open source projects, many of them with an unknown origin and insecure update mechanisms. It is clear that software today is mostly assembled instead of built, so organizations must be proactive about open-source security risk management. Moreover, 64% of all vulnerabilities have no fixes available, thus making it even more important for businesses to apply secure software supply chain practices.

These findings are echoed by Javed Hasan, CEO and co-founder of Lineaje. He stresses that even popular and well-known open source software can have malicious tampering, and it is important for software developers to have tools to establish the origin and legitimacy of their code. Ultimately, everyone benefits when organizations take a proactive approach to software security management and invest in code governance and supply chain tools.

Lineaje is a software security and risk management company that focuses on helping organizations analyze, optimize, and protect their software supply chains. Founded in 2016, the company has helped many organizations across various industries to secure and track their software components for a secure-by-design approach. Lineaje’s products are environment agnostic and help businesses (large and small) to gain visibility into their worldwide software supply chain.

See also  Crowdstrike Holdings Inc. Class A - Technical Data Analysis (CRWD)

Frequently Asked Questions (FAQs) Related to the Above News

Please note that the FAQs provided on this page are based on the news article published. While we strive to provide accurate and up-to-date information, it is always recommended to consult relevant authorities or professionals before making any decisions or taking action based on the FAQs or the news article.

Share post:

Subscribe

Popular

More like this
Related

Ripple XRP Lawsuit Update: Potential $1 Milestone Hinges on July Outcome

Will Ripple's XRP hit $1? Legal battle outcome could propel price surge past milestone. Stay updated with the latest news.

Ripple’s XRP Price Surge: Legal battle outcome could propel asset past $1 milestone

Will Ripple's XRP hit $1? Legal battle outcome could propel price surge past milestone. Stay updated with the latest news.

Exciting News: Bitcoin and Rollblock (RBLK) Set to Skyrocket in 2024!

Exciting News: Bitcoin and Rollblock (RBLK) predicted to skyrocket in 2024! Don't miss out on potential gains with these promising altcoins.

Google Aims to Ditch Apple for Search Revenue, US Lawsuit Impacts Relationship

Google aims to reduce reliance on Apple for search revenue. US lawsuit impacts relationship. Will Google lose billions in revenue?