SHARE
Facebook X Pinterest WhatsApp

Report: Don’t Neglect Open Source Security

thumbnail
Report: Don’t Neglect Open Source Security

When using open source software, visibility in the application lifecycle helps decision-makers gather the information they need to make critical decisions and resolve risk.

Jun 9, 2023

In the past few years, open source usage has spiked as companies seek digital transformation and grapple with pandemic-related disruption. While the market has grown, security hasn’t, according to a new report.

In its 8th edition this year, the 2023 “Open Source Security and Risk Analysis” (OSSRA) report from Synopsys continues to study the current state of open source security, from licensing to compliance, and its most pressing risks.

Of the more than 1700 open-source codebases examined by the report, a shocking 84% contained at least one known open-source vulnerability. These findings present a stark reality for many businesses. Open source is a vital part of maintaining technology budgets and encouraging experimentation, but without strategic boundaries and monitoring, the risks far outweigh the benefits.

Many sectors experienced rapid growth in open source usage—aerospace, transportation, and logistics, for example, experienced a 97% growth in the past five years. But vulnerabilities have increased in step, which puts many of our major commercial sectors at serious risk.

See also: Log4j, Like COVID, is Endemic and Still Requires Attention

What companies can do to utilize open source safely

The report identified two specific red flags for companies—using open source without a corresponding license and allowing code to sit unmonitored and unused for extended periods.

For the first red flag, pursuing a license agreement may seem to be the antithesis of open source, but even free code should offer boundaries for use. When companies understand the parameters of the code and actively agree, this could reduce the risk of later conflicts. In the second, continually monitoring code usage helps ensure that required security patches and updates don’t fall through the cracks.

Companies should strive for complete visibility, even in open source. This visibility in the application lifecycle helps decision-makers gather the information they need to make critical decisions and resolve risk. The study also makes clear, once again, that companies using any third-party software should act as if it contains open source because it most likely does. It’s better to be prepared than surprised.

thumbnail
Elizabeth Wallace

Elizabeth Wallace is a Nashville-based freelance writer with a soft spot for data science and AI and a background in linguistics. She spent 13 years teaching language in higher ed and now helps startups and other organizations explain - clearly - what it is they do.

Recommended for you...

Beyond Procurement: Optimizing Productivity, Consumer Experience with a Holistic Tech Management Strategy
Rishi Kohli
Jan 3, 2026
Smart Governance in the Age of Self-Service BI: Striking the Right Balance
The AI Executive Order Creates Uncertainty, Not Clarity. Here’s How to Navigate It.
RTInsights Team
Dec 26, 2025
RPA vs. AI Automation: Is Robotic Process Automation Being Replaced?

Featured Resources from Cloud Data Insights

Cloud Evolution 2026: Strategic Imperatives for Chief Data Officers
Why Network Services Need Automation
The Shared Responsibility Model and Its Impact on Your Security Posture
The Role of Data Governance in ERP Systems
Sandip Roy
Nov 28, 2025
RT Insights Logo

Analysis and market insights on real-time analytics including Big Data, the IoT, and cognitive computing. Business use cases and technologies are discussed.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.