sonatype第9年度软件供应链安全报告-英-62页_5mb
报告摘要
-
Open Source Consumption Trends: Global usage of Java, JavaScript, Python, and .NET ecosystems continues to grow. Maven Central saw 25% YoY growth, npm exceeded 2020 growth, Python increased by 31%, and NuGet showed the highest growth at 43%. However, malicious packages tripled YoY, and 85% of Maven Central projects are inactive despite fixes being available.
-
Security Challenges: 96% of vulnerable downloads are avoidable by using updated versions. Common issues include poor dependency management, lack of maintenance (11% of Java projects are maintained), insufficient code reviews (2% fully adhere), and slow vulnerability patching (37% of downloads are from reactive versions). Auto-upgrades reduced reactive downloads by 14%.
-
Geopolitical Regulations: The US, EU, and U.K. are leading in regulations like CISA’s Open Source Roadmap, NIS2, and the Secure by Design principles. Canada and Australia are following, but over-regulation concerns exist, especially with liability implications for open source.
-
AI in Development: 97% of developers use AI tools like ChatGPT and GitHub Copilot, saving time but raising concerns about code quality, job displacement, and copyright issues from training datasets. LLM growth expanded into non-generative AI areas, but security vulnerabilities persist.
-
Supply Chain Risks: Open source license threats (39% risk exposure), AI copyright issues, and complex micro-licensing in research make compliance challenging. Additionally, 60% worry about illegal code use, especially in large organizations.
-
Maturity and Investment: Engineering teams score low in process automation and open source risk integration. Enterprises are investing heavily in SBOMs, SCAP, and vulnerability scanning (68%+), but only 53% generate full SBOMs for all apps, indicating room for improvement.
-
Consumption Behavior: Developers universally favor simpler tools with fewer concerns, exhibiting learning curve challenges when transitioned to advanced solutions. Regional differences exist but maturity barriers affect consistent practice implementation.
In conclusion, proactive measures incorporating automation, SBOM generation, and AI integration with clear governance are necessary to maintain a secure and efficient software supply chain.
试读结束,高清完整版pdf/doc/ppt,请点下载