sonatype-2020年软件供应链状况报告(英文)-2020.8-44页_7mb
报告摘要
2020 State of the Software Supply Chain Report Summary
Core Content
This report provides an in-depth analysis of the state of the software supply chain in 2020, focusing on the increasing use of open source software (OSS) and the associated security challenges. It highlights the growing number of cyber attacks targeting the OSS supply chain and the importance of efficient and secure practices in managing these dependencies.
Main Points
- Global OSS Usage: In 2020, over 1.5 trillion OSS component and container download requests were expected globally.
- Cyber Attacks: There was a 430% YoY increase in next-gen cyber attacks targeting open source software projects.
- Vulnerability Prevalence: 11% of OSS components used in applications have known vulnerabilities.
- Security Practices: High-performing enterprise development teams are 26x faster in detecting and remediating vulnerabilities and are 51% more likely to create a Software Bill of Materials (SBOM).
- OSS Governance: High performers are 59% more likely to enforce OSS governance in Continuous Integration (CI) environments.
- Dependency Management: Exemplary projects update dependencies 530x faster and have 2.8x more commits than others.
- OSS Breaches: 21% of enterprises experienced open source breaches in 2020.
Key Findings
Chapter 1: Open Season on Open Source
- Next-Gen Attacks: These attacks are more dangerous than legacy ones, as they involve malicious code injection directly into open source projects.
- Examples: Notable attacks include the event-stream and Octopus Scanner incidents.
- Attack Vectors: Common methods include typosquatting, credential theft, and malicious code injection during package updates.
- Impact: Attackers can exploit vulnerabilities within 72 hours of public disclosure, as seen in the Equifax breach and SaltStack incident.
Chapter 2: Open Source: Supply and Demand
- JavaScript: Over 1 trillion JavaScript packages are expected to be downloaded in 2020. The average monthly download traffic for npm packages has grown by over 100% YoY.
- Java: Around 7.6 million Java developers are active, with 226 billion component downloads from Maven Central in 2019.
- .NET: .NET developers saw a 177% increase in NuGet package downloads, reaching 44.8 billion in 2020.
- DockerHub: Container image pulls reached 8 billion in January 2020, with 2.2 million new images pushed in the past year.
Chapter 3: Identifying Exemplary Open Source Suppliers
- Exemplar Projects: These are defined by fast Mean Time to Update (MTTU) and low stale dependency count.
- Performance Metrics:
- Exemplars update dependencies 530x faster.
- They have 2.8x more commits and 1.5x more frequent releases.
- Exemplars have 2.9x fewer dependencies and are 2.5x more popular.
- Team Size: Exemplar teams are 1.4x larger on average and are 173x less likely to have outdated dependencies.
Chapter 4: High Performance Teams and OSS Management
- High Performers: These teams are 26x faster in detecting and remediating OSS vulnerabilities and are 51% more likely to use SBOM.
- OSS Governance: High performers are 59% more likely to enforce governance in CI environments.
- Variables Impacting Performance: Key factors include dependency update frequency, CI practices, and team size.
Chapter 5: Trust and Integrity in the Software Supply Chain
- Vulnerability Awareness: Only 17% of organizations become aware of new vulnerabilities within a day of public disclosure.
- Mitigation Delay: 51% of participants take more than a week to respond to vulnerabilities.
- Vulnerability Impact: On average, 38 known OSS vulnerabilities are found per application.
- Government Standards: The NIST introduced new standards requiring SBOMs and OSS security checks.
Chapter 6: The Changing OSS Landscape
- Social Activism: Increasingly, social activism is influencing the OSS landscape.
- Government Standards: Governments are implementing new standards to secure software supply chains.
- United States, United Kingdom, Australia: These countries are applying new regulations to enhance software supply chain security.
Summary of Key Statistics
- 1.5 trillion OSS downloads expected in 2020.
- 430% YoY growth in cyber attacks targeting open source projects.
- 11% of OSS components have known vulnerabilities.
- 38 known OSS vulnerabilities per application on average.
- 373,000 enterprise downloads of OSS components per year.
- 530x faster dependency updates for exemplary projects.
- 26x faster vulnerability detection and remediation for high performers.
- 51% more likely to create SBOM for high performers.
- 59% more likely to enforce OSS governance in CI for high performers.
- Nearly 40% of npm packages rely on code with known vulnerabilities.
- 21% of enterprises experienced open source breaches in 2020.
Conclusion
The report underscores the critical need for rapid response, efficient dependency management, and strong security practices in the software supply chain. It also highlights the growing reliance on open source and the urgent need for SBOMs, SCA tools, and OSS governance to mitigate the risks associated with the expanding attack surface and increasing demand for open source components.
试读结束,高清完整版pdf/doc/ppt,请点下载