More and more companies are now worried about open source security

open source
Image Credit: Alpha Stock Images (Image credit: Image Credit: Alpha Stock Images)

Businesses are slowly moving away from open source software, due to growing fears of security risks that come from open source elements, new research has shown.

Virtualization giant VMware recently released a report that states that the number of companies willing to deploy open source software in production environments fell from 95% last year, to 90% this year. 

The two biggest concerns that are forcing companies to look elsewhere are the ability to identify and address vulnerabilities found in open source software. In fact, dependency on the community to address flaws and vulnerabilities is at the top of the list (61%), followed by increased security risks (53%), and the lack of service-level agreements (SLA) for patches from the community (50%). 

Too many tools, manual tasks, and people

To address the issue, businesses would love to see improvements in packaging security, as open source software packaging is essential in securing the supply chain, the report claims.

Apparently, there are too many tools, too many manual tasks, and too many teams working on packaging at most companies, which makes the process sluggish, inefficient and risky.

When asked which software packaging capabilities would improve security, almost two-thirds (60%) would appreciate immediate access to trusted security patches to applications or runtimes, dependencies, and operating system components, while half (55%) want centralized visibility to all scans, as it would simplify security audits. Half (51%) also want to automate CVE and virus scanning for every container.

While open source software remains an indispensable part of every project, this is not the first time questions of security have been raised. Last June, cybersecurity firm Snyk, together with the Linux Foundation, published a report claiming open-source software poses a “significant security risk”.

Based on a survey of more than 550 respondents, as well as data pulled from 1.3 billion open source projects via Snyk Open Source, the report states that two in five (41%) firms are not confident in the security of their open source code.

The average application development project, it was found, has 49 vulnerabilities, as well as 80 direct dependencies. Usually, it now takes 110 days to remedy a vulnerability in an open source project, up from 49 days four years ago.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Holographic representation of cloud computing over open businessman's hand
Businesses are struggling to address vulnerabilities hidden in phantom dependencies
API
Businesses are being plagued by API security risks - with nearly 99% affected
Security
Removing software supply chain blind spots that put public sector organizations at risk
A developer writing code
Open source software is now a multi-billion dollar industry
Hacker Typing
Racing against time on a menacing caldera: survey finds majority of organizations take days to tackle critical vulnerabilities, each of them a potential open goal for cybercriminals
Closing the cybersecurity skills gap
The critical need for watertight security across the IT supply chain
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras