close search bar

Sorry, not available in this language yet

close language selection

OPEN SOURCE SECURITY AND RISK ANALYSIS REPORT

2023 OSSRA Report
Open Source is Everywhere

96%

Open Source Graph | 96% codebases open source

76%

Open Source Graph | 76% codebases open source

96% of scanned codebases contained open source

76% of code in codebases was open source

open source security risk

84%

open source vulnerabilities | 84% of open source codebases

48%

open source high risk vulnerabilities | 48% of open source codebases

84% of codebases contained at least one vulnerability

48% of codebases contained high-risk vulnerabilities

89% were more than 4 years out of date

91% contained components that weren't the current version

91% had received no development activity in the last 2 years

88% contained components with no activity in the last 2 years and contained components that weren't the latest version

Percentage of codebases containing open source by industry

Percentage of code that was open source by industry

Aerospace, Aviation, Automotive, Transportation, Logistics

open source risk by industry
open source risk by industry graph
open source risk

Big Data, AI, BI, Machine Learning

Big Data, AI, BI, Machine Learning open source risk
Big Data, AI, BI, Machine Learning open source risk
Big Data, AI, BI, Machine Learning open source risk

Computer Hardware and Semiconductors

Computer Hardware and Semiconductors open source
Computer Hardware and Semiconductors open source risk
Computer Hardware and Semiconductors open source risk

Cybersecurity

Cybersecurity open source
Cybersecurity open source risk
Cybersecurity open source risk

EdTech

EdTech open source
EdTech open source risk
EdTech open source risk

Energy and Clean Tech

Energy and Clean Tech open source
Energy and Clean Tech open source risk
Energy and Clean Tech open source risk

Enterprise Software/SaaS

Enterprise Software/SaaS open source
Enterprise Software/SaaS open source risk
Enterprise Software/SaaS open source risk

Financial Services and FinTech

Financial Services and FinTech open source
Financial Services and FinTech open source risk
Financial Services and FinTech open source risk

Healthcare, Health Tech, Life Sciences

Healthcare, Health Tech, Life Sciences open source
Healthcare, Health Tech, Life Sciences open source risk
Healthcare, Health Tech, Life Sciences open source risk

Internet and Mobile Apps

Internet and Mobile Apps open source
Internet and Mobile Apps open source risk
Internet and Mobile Apps open source risk

Internet and Software Infrastructure

Internet and Software Infrastructure open source
Internet and Software Infrastructure open source risk
Internet and Software Infrastructure open source risk

Internet of Things

IoT open source
IoT open source risk
IoT open source risk

Manufacturing, Industrials, Robotics

Manufacturing, Industrials, Robotics open source
Manufacturing, Industrials, Robotics open source risk
Manufacturing, Industrials, Robotics open source risk

Marketing Tech

Marketing Tech open source
Marketing Tech open source risk
Marketing Tech open source risk

Retail and eCommerce

Retail open source
Retail open source risk
Retail open source risk

Telecommunications and Wireless

Telecommunications open source
Telecommunications open source risk
Telecommunications open source risk

Virtual Reality, Gaming, Entertainment, Media

Gaming and Entertainment open source
Gaming and Entertainment open source risk
Gaming and Entertainment open source risk

The annual “Open Source Security and Risk Analysis” (OSSRA) report, now in its 8th edition, examines vulnerabilities and license conflicts found in roughly 1,700 codebases across 17 industries. The report offers recommendations for security, legal, risk, and development teams to better understand the security and risk landscape accompanying open source development and use.

OPEN SOURCE IS EVERYWHERE

Open source continues to prove its staying power, serving as the foundation for the vast majority of commercial codebases. In fact, it’s so intertwined in modern development that code owners often don’t know the open source components in their own software.

SECURITY RISK IS PREVALENT

The overall percentage of codebases containing security vulnerabilities remains troublingly high. After a year of modest progress, there was another slight uptick (4%) in vulnerabilities during 2022. 

While overall vulnerabilities were slightly up, the percentage of codebases with high-risk vulnerabilities was down 2% from last year, to 48%. Also promising was fewer instances of Log4J, which was found in 11% of audited Java codebases this year, down from 15%. While an improvement, this points to a larger trend of organizations failing to implement patches.

OPERATIONAL RISK IS PERVASIVE

A worrying number of codebases contained open source that had no development activity and no user updates in the last two years. When no feature upgrades, code improvements, or security remediation occurs for 24 months, it’s likely the project is no longer being maintained at all.

KEY INDUSTRIES REMAIN VULNERABLE

The same story emerged across all industry sectors: Open source was present in almost every codebase, composed the majority of the total codebases, and was vulnerable to exploit and attack. Only a comprehensive inventory of all software in use by an organization can help mitigate this business risk.

2023 OSSRA Report A deep dive into the state of open source security, licensing, code quality, and maintenance risk

OSSRA 2023 Report Cover

2023 Open Source Security and Risk Analysis Report

2023 OSSRA Report