State of Software Security: open-source Edition
veracode.com
veracode.com
"We looked at the most popular libraries in 2019 vs. 2020, as well as the most popular libraries with known vulnerabilities in 2019 vs. 2020...".
- "Most libraries are never updated...79 percent of the time, developers never update third-party libraries after including them in a codebase"
- "When alerted to vulnerable libraries, developer can act quickly. In fact, nearly 17 percent of vulnerable libraries are fixed within an hour of the scan that alerted the developer to the vulnerability; 25 percent are fixed within seven days..."
- "...Most open source security flaws require only minor fixes. 92 percent of library flaws can be fixed with an update, and 69 percent of updates are a minor version change or less..."
That's the cool, flashy, automatable part of security. But IMO the boring, manual parts (operational security, security training, etc.) are too often ignored.
On the other hand, Veracode's central product is a scanner. I cannot even begin to imagine how to consistently evaluate the boring, manual, operational parts of a security program in the context of open source libraries.
How does one assess the security training and operations of a library developed and maintained by three people?