1. https://appdevelopermagazine.com/devops
  2. https://appdevelopermagazine.com/devsecops-7th-annual-community-survey-results/
4/15/2020 11:15:41 AM
DevSecOps 7th annual Community Survey results
Sonatype,DevSecOps,Community Survey
/DevSecOps-7th-annual-Community-Survey-results-App-Developer-Magazine_znyqkbgh.jpg
App Developer Magazine
DevSecOps 7th annual Community Survey results

DevOps

DevSecOps 7th annual Community Survey results


Wednesday, April 15, 2020

Brittany Hainzinger Brittany Hainzinger

Sonatype published findings from DevSecOps 7th annual Community Survey. The survey pulls back the curtain on successful DevSecOps practices, significant influences on developer satisfaction, trends in secure coding, and application breaches. 

Sonatype published findings from its seventh annual DevSecOps Community Survey, based on responses from 5,045 software engineering professionals. The survey, developed and conducted in partnership with Carnegie Mellon’s Software Engineering Institute, CloudBees, DevOps Institute, DevOps.com, DevSecOps Days, NowSecure, Security Boulevard, Verica, and All Day DevOps, pulls back the curtain on successful DevSecOps practices, significant influences on developer satisfaction, trends in secure coding, and application breaches. 

The survey reveals that development velocity is accelerating with 55% of respondents deploying code to production at least once per week, compared to 47% of respondents in 2019. Findings also show how engineering teams supported by mature DevOps practices are more likely to integrate automated security tooling into their development lifecycle. The most popular automated security investments are web application firewalls (59%), open-source governance (44%), and intrusion detection (42%).

Mature DevOps teams also demonstrate 1.6x higher job satisfaction rates compared to their immature peers. Furthermore, mature teams are 2.2x more likely to invest in container security, 2.1x more likely to invest in Dynamic Analysis Security Testing, and 1.9x more likely to invest in Software Composition Analysis.

“DevSecOps transformations are proving critical – not just to improve productivity and application security - but to ensure developer delight. This year, mature DevOps teams are properly integrating and automating security tools almost 2x more often than less mature teams. We also found developers in mature DevOps teams are 1.6x more likely to recommend their employers in today’s tight job market and 1.3x more likely to get work done,” said Derek Weeks, Vice President at Sonatype. 

Mature DevOps teams are more aware of breaches: 28% of mature organizations are aware of an open-source component-related breach in the past 12 months, compared to just 19% of respondents with immature DevOps practices. While breaches appear higher for mature DevOps practices, industry advocates point to cultural advantages that reward open communication, welcome new information, and encourage tighter collaboration between developer and security tribes.

Happy developers pay more attention to security: Happy developers are 3.6x less likely to neglect security when it comes to code quality and 1.3x more likely to follow open source policies. They are also 2.3x more likely to have automated security tools in place. Developers working within mature DevOps practices are 1.5x more likely to enjoy their work, and 1.6x more likely to recommend their employer to prospects.

Tooling and training show a strong correlation with DevOps delight: Happier developers are 1.3x more likely to be informed of security issues from their integrated tooling compared to their grumpier counterparts. But improved tooling and close collaboration with security teams also paid off for happier developers, as they are 3.8x less likely to rely on rumors when it comes to security notifications. Developers who receive training on how to code securely are also 5x more likely to enjoy their work.






Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Featured Stories


Tether QVAC SDK Powers AI Across Devices and Platforms
Tether QVAC SDK Powers AI Across Devices and Platforms Wednesday, April 22, 2026


APAC 5G expansion to fuel 347B mobile market by 2030
APAC 5G expansion to fuel 347B mobile market by 2030 Tuesday, April 21, 2026




How AI is causing app litter everywhere
How AI is causing app litter everywhere Tuesday, April 21, 2026


The App Economy Is Thriving
The App Economy Is Thriving Monday, April 20, 2026


NIKKE 3.5 anniversary update livestream coming soon
NIKKE 3.5 anniversary update livestream coming soon Friday, April 17, 2026


New AI tool targets early dementia detection
New AI tool targets early dementia detection Thursday, April 16, 2026


Jentic launch gives AI agents api access
Jentic launch gives AI agents api access Wednesday, April 15, 2026


Experts warn ai-generated health content risks misinterpretation without human oversight
Experts warn ai-generated health content risks misinterpretation without human oversight Wednesday, April 15, 2026


Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines
Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines Tuesday, April 14, 2026


AccuWeather Launches ChatGPT Integration for Live Weather Updates
AccuWeather Launches ChatGPT Integration for Live Weather Updates Tuesday, April 14, 2026


Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Get More App News



/sites/themes/prod/assets/js/less.js"> ' ' %>