1. https://appdevelopermagazine.com/security
  2. https://appdevelopermagazine.com/the-use-of-vulnerable-open-source-components-putting-more-software-at-risk/
10/18/2016 11:02:08 AM
The use of vulnerable open source components putting more software at risk
Software Security,Open Source,DevOps
/Veracode-State-of-Security-Report-App-Developer-Magazine_liboicls.jpg
App Developer Magazine
The use of vulnerable open source components putting more software at risk

Security

The use of vulnerable open source components putting more software at risk


Tuesday, October 18, 2016

Richard Harris Richard Harris


Veracode has released the findings in its annual State of Software Security Report (SoSS). The seventh edition of the report presents metrics drawn from code-level analysis of billions of lines of code across 300,000 assessments performed over the last 18 months. The report revealed that the continued and persistent use of components in software development is creating systemic risk in our digital infrastructure. However, they also found that companies achieve accelerated benefits when their application security programs reach maturity. These findings indicate that the growing trend of focusing on digital risk at the application layer and building security into DevOps processes (DevSecOps) can yield great results for organizations in reducing risk without slowing down software development.

A few key highlights:

- 97 percent of Java applications have at least one vulnerability due to the reuse of software components

- Healthcare is still struggling to fix vulnerabilities despite a string of breaches. Government however seems to have learned its lesson from OPM and is fixing its security holes

- Commercially developed applications are less secure than ones developed in-house. 75 percent of commercial applications fail basic security checks compared to 61 percent of internally developed applications

Their analysis revealed the growing risk caused by the proliferation of vulnerable open-source components. Veracode found that a single popular component with a critical vulnerability spread to more than 80,000 other software components, which were in turn then used in the development of potentially millions of software programs. Approximately 97 percent of Java applications contained at least one component with a known vulnerability.

The research also highlights the challenges that still exist in software development more broadly. For example, 60 percent of applications failed basic security requirements upon first scan. However, the report found that when companies follow best practices and implement programs with consistent policies and practices for secure development, they are able to remediate vulnerabilities at a higher rate. The study showed that the top quartile of companies fix almost 70 percent more vulnerabilities than the average organization. Additionally, best practices like remediation coaching and eLearning can improve vulnerability fix rates by as much as six-times. Developers who test unofficially using Developer Sandbox scanning improve policy-based vulnerability fix rates by about two-times.



Read more: http://interactive.veracode.com/state-of-software-...




Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Featured Stories


New AI tool targets early dementia detection
New AI tool targets early dementia detection Thursday, April 16, 2026


Jentic launch gives AI agents api access
Jentic launch gives AI agents api access Wednesday, April 15, 2026




Experts warn ai-generated health content risks misinterpretation without human oversight
Experts warn ai-generated health content risks misinterpretation without human oversight Wednesday, April 15, 2026


Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines
Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines Tuesday, April 14, 2026


AccuWeather Launches ChatGPT Integration for Live Weather Updates
AccuWeather Launches ChatGPT Integration for Live Weather Updates Tuesday, April 14, 2026


Stop Using Business Jargon: 5 Ways Buzzwords Damage Job Performance
Stop Using Business Jargon: 5 Ways Buzzwords Damage Job Performance Tuesday, April 14, 2026


IT spending rises as banks balance legacy and innovation
IT spending rises as banks balance legacy and innovation Monday, April 13, 2026


Tech hiring slumps as Software Developer job postings fall
Tech hiring slumps as Software Developer job postings fall Monday, April 13, 2026


AI is becoming more widespread in collaboration tools
AI is becoming more widespread in collaboration tools Thursday, April 9, 2026


FCC prohibits new foreign router models citing critical infrastructure risks
FCC prohibits new foreign router models citing critical infrastructure risks Thursday, April 9, 2026


Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Get More App News



/sites/themes/prod/assets/js/less.js"> ' ' %>