SHARE
Facebook X Pinterest WhatsApp

Report: Don’t Neglect Open Source Security

thumbnail
Report: Don’t Neglect Open Source Security

When using open source software, visibility in the application lifecycle helps decision-makers gather the information they need to make critical decisions and resolve risk.

Jun 9, 2023

In the past few years, open source usage has spiked as companies seek digital transformation and grapple with pandemic-related disruption. While the market has grown, security hasn’t, according to a new report.

In its 8th edition this year, the 2023 “Open Source Security and Risk Analysis” (OSSRA) report from Synopsys continues to study the current state of open source security, from licensing to compliance, and its most pressing risks.

Of the more than 1700 open-source codebases examined by the report, a shocking 84% contained at least one known open-source vulnerability. These findings present a stark reality for many businesses. Open source is a vital part of maintaining technology budgets and encouraging experimentation, but without strategic boundaries and monitoring, the risks far outweigh the benefits.

Many sectors experienced rapid growth in open source usage—aerospace, transportation, and logistics, for example, experienced a 97% growth in the past five years. But vulnerabilities have increased in step, which puts many of our major commercial sectors at serious risk.

See also: Log4j, Like COVID, is Endemic and Still Requires Attention

What companies can do to utilize open source safely

The report identified two specific red flags for companies—using open source without a corresponding license and allowing code to sit unmonitored and unused for extended periods.

For the first red flag, pursuing a license agreement may seem to be the antithesis of open source, but even free code should offer boundaries for use. When companies understand the parameters of the code and actively agree, this could reduce the risk of later conflicts. In the second, continually monitoring code usage helps ensure that required security patches and updates don’t fall through the cracks.

Companies should strive for complete visibility, even in open source. This visibility in the application lifecycle helps decision-makers gather the information they need to make critical decisions and resolve risk. The study also makes clear, once again, that companies using any third-party software should act as if it contains open source because it most likely does. It’s better to be prepared than surprised.

thumbnail
Elizabeth Wallace

Elizabeth Wallace is a Nashville-based freelance writer with a soft spot for data science and AI and a background in linguistics. She spent 13 years teaching language in higher ed and now helps startups and other organizations explain - clearly - what it is they do.

Recommended for you...

Cleaning up the Slop: Will Backlash to “AI Slop” Increase This Year?
Henry Young
Feb 13, 2026
On a Trust-Building Trajectory: AI in Network Automation
Brad Haas
Feb 12, 2026
AI as a Co-Pilot, Not a Replacement: The Ethical Path to Integrating AI into Business
Mohamed Yousuf
Feb 8, 2026
Bye to the Beta Phase of AI Agents: How to Succeed in 2026
Gastón Milano
Feb 6, 2026

Featured Resources from Cloud Data Insights

How Can AI Improve Industrial Inventory Management (Practical Use Cases)
Luke Crihfield
Feb 17, 2026
Why Intelligence Without Authority Cannot Deliver Enterprise Value
Harsha Kumar
Feb 17, 2026
Real-time Analytics News for the Week Ending February 14
Why Satellite Connectivity Sits at the Heart of Enterprise Network Resilience
Fánan Henriques
Feb 14, 2026
RT Insights Logo

Analysis and market insights on real-time analytics including Big Data, the IoT, and cognitive computing. Business use cases and technologies are discussed.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.