October 3, 2023 – DevOps Enterprise Summit - Las Vegas – Sonatype, the pioneer of software supply chain management, today released its 9th Annual State of the Software Supply Chain Report. This year’s report highlights alarming open source software (OSS) and software supply chain security trends, while also looking at how arming developers with better, more consistent development tools and best practices can save them and their organizations a significant amount of time and money. Noteworthy findings in the report include:
“A lot of maintainers are very diligent – Big Tech companies go out of their way to hire talented people to maintain libraries they rely on,” says Brian Fox, CTO at Sonatype. “Our industry needs to direct its efforts towards the right place. The fact that there’s been a fix for almost all downloads of components with a known vulnerability tells us an immediate focus should be supporting developers on becoming better decision-makers, and giving them access to the right tools. The goal is to help developers be more intentional about downloading open source software from projects with the most maintainers and the healthiest ecosystem of contributors. This will not only create safer software, but also recoup nearly two weeks of wasted developer time each year."
Amidst rising software supply chain attacks, there’s also a continued disconnect between perceived security and reality in software development:
Developers play a pivotal role in driving progress, innovation, and excellence. Findings this year further highlight the direct relationship between developer productivity and access to superior tools and high-quality open source components. While investigating solutions for reducing security risks and time wasting, Sonatype discovered that:
“Impactful change necessitates clear direction,” adds Fox. “For both better and worse, today’s software organizations face an overwhelming amount of options for addressing these issues – from a multitude of frameworks to weekly governmental guidance, and more. All that choice is ripe to create paralysis, making it hard to get started.”
Among the spike in software supply chain vulnerabilities, there are signs of developers taking measures to improve efficiencies and security posture. The report shows the use of AI/ML components in software development surging by 135% in less than a year, largely owing to the massive efficiencies the technology affords software developers, in addition to how quickly AI/ML components can be integrated into software development workflows. That said, developers and organizations face significant challenges in developing their own AI products.
“While AI/ML technology has become more accessible than ever, there are still significant implementation challenges. Developers and data scientists have to choose from hundreds of thousands of options for models and libraries,” says Stephen Magill, Vice President of Innovation at Sonatype. “Choosing open source solutions comes with all of the familiar requirements around managing open source security risk. Choosing proprietary solutions can come with high costs. And in both cases, licensing of both the models and the model outputs can be very uncertain.”
To read the full report, visit The 9th Annual State of the Software Supply Chain Report.
Note to Editors:
Sonatype’s ninth annual State of the Software Supply Chain Report blends a broad set of public and proprietary data and analysis, including dependency update patterns for more than 400 billion Maven Central downloads and thousands of open source projects, survey results from 621 engineering professionals, and the assessment of hundreds of thousands key enterprise applications. This year’s report also analyzed operational supply, demand, and security trends associated with the Java (Maven Central), JavaScript (npmjs), Python (PyPI), and .Net (nuget) ecosystems.
About Sonatype
Sonatype is the software supply chain management company. Recognized by globally renowned analysts as a leader in the industry, Sonatype enables organizations to innovate faster in a highly competitive market. We allow engineers to develop software fearlessly and focus on building products that power businesses. Sonatype researchers have analyzed more than 120 million open source components – 40x more than its competitors – and the Sonatype platform has automatically blocked over 245,000 malicious components from entering developers’ code. Enabling high-quality, secure software helps organizations meet their business needs and those of their customers and partners. More than 2,000 organizations, including 70% of the Fortune 100 and 15 million software developers, rely on our tools and guidance to be ambitious, move fast and do it securely. To learn more about Sonatype, please visit www.sonatype.com.