New Sonatype Survey Says Applications Are at Least 80%

New Post Public Reply Private Reply Replies (0) Message Board
News Desk 2018
New Sonatype Survey Says Applications Are at Least 80% Component-Based, Yet 76% of Organizations Lack Component Management

SILVER SPRING, MD--(Marketwired - Apr 30, 2013) - Sonatype, the leader in Component Lifecycle Management (CLM), today announced the findings of its annual Open Source Software Development Survey that looks to identify how organizations adopt, use and support open-source software (OSS). This year's survey shows that open-source component use continues to skyrocket with applications now more than 80 percent component-based, while at the same time organizations continue to struggle with establishing policy to secure and govern component use. According to the survey, 76 percent of organizations have no component management policies in-place.

Now in its third year, the 2013 survey saw record participation from more than 3,500 developers, architects and managers across all industries, company sizes and geographic regions -- making it the largest, most comprehensive survey of its kind. The survey findings show that organizations of all sizes have embraced open-source components as the building blocks of modern software. But, the lack of internal controls and a failure to address security vulnerabilities throughout the software development lifecycle threatens the integrity of the software supply chain and exposes organizations to massive, unmanaged risk.

Also today, Sonatype announced Sonatype CLM, the first and only solution to secure the entire component lifecycle -- from design, development and deployment through to production. Ushering in a new era of application security aimed at eliminating risk in the modern software supply chain, Sonatype CLM addresses the security needs of the $86 billion custom application software market. It is also the first solution to directly address the 2013 Open Web Application Security Project (OWASP) Top Ten A9 provision: using components with known vulnerabilities.

Key Finding: Open Source Software is Vital to Modern, Agile Development Open-source component usage has exploded. In 2012, Sonatype's Central Repository registered eight billion component downloads, an 800 percent increase in activity since its inception. Nearly 80 percent of the organizations surveyed report components found in Sonatype's Central Repository to be important or critical to their development efforts. An overwhelming 86 percent of those surveyed believe their applications are at least 80 percent open source with the remaining 20 percent custom components and code, illustrating a dramatic shift in how mission-critical software is built. This paradigm shift is forcing companies to rethink how they manage risk in the age of agile, component-based software development.

Key Finding: Lack of Open Source Policy and/or Enforcement Puts Organizations at Risk While reliance on open-source components increases year-over-year, limitations on the visibility, control and management of their use continues to be a problem. Of those large organizations surveyed (companies with > 500 developers), an astonishing 76 percent have no control over what components are being used in software development projects and even more alarming is that 65 percent don't maintain an inventory of components used in production applications. Like operating systems or database, open-source components represent a rich attack vector for hackers to exploit given their commonality across organizations and applications.

Despite the widespread acceptance of component-based development, 57 percent of those surveyed lack any policy governing component usage. Organizations with open-source policies in place share that enforcement is a challenge and not a top priority. Developers cite the biggest problem to open-source policy is that it slows development, expectations are unclear or policy is unenforced, and that problems are found too late in the development lifecycle.

The lack of policy enforcement may be due, in part, to confusion over who owns or is responsible for monitoring and managing open-source usage. No single, centralized authority governing open source emerged in the organizations that indicated having a corporate policy. Other contributing factors are that large organizations often are unaware that open source is even being used. Open-source standardization is seen more frequently in organizations with less than 500 developers -- but that doesn't mean large enterprises aren't using open-source frameworks and components. For developers on large teams, 44 percent say they are standardizing on an open-source development infrastructure stack, with 33 percent stating, "It's not our corporate standard, but tons of people use it."

Key Finding: Security Takes a Back Seat to Developer Velocity In addition to gauging how development teams embrace open-source components, the 2013 survey sought to determine how developers, architects and managers balance the need for speed with the need for security. For large enterprises ( > 500 developers) more than half shared that developers don't focus on security at all. Nearly 20 percent of this group shared they know application security is important but they don't have the time to spend on it, while almost one-third deferred responsibility to the security and risk management group entirely.

Even organizations with an open-source policy are doing very little to prevent security vulnerabilities from creeping in. Only 25 percent of respondents, or one in four organizations surveyed, must prove they're not using components with known vulnerabilities. But due to the high volume of dependencies for each component (often tens or 100s) and the frequency of updates and changes (a typical component is updated four times per year), all organizations concede it's near impossible to monitor and maintain accurate component intelligence.

A Call to Action Organizations are exposed to significant risks caused by their increasing reliance on open-source components. Component flaws are exceeding common -- more than 70 percent of applications contain components with known security flaws classified as severe or critical. Everything from Big Data, to cloud and mobile applications are exposed to unmanaged risk. While developers are on the frontlines of application security, making choices every day that affect the quality and security of the applications that run the world, the pressure to add more features and put applications into production quickly comes at a devastating tradeoff -- to go fast or be secure. The survey findings suggest an overwhelming desire by developers for a non-intrusive way to proactively identify, govern and fix flawed components throughout the development lifecycle.

"Our world runs on software and software runs on open-source components," said Wayne Jackson, CEO of Sonatype. "Securing networks and operating systems is not enough to protect the critical data housed in modern applications. As the frontline of defense, developers must be empowered not burdened. A new approach to security is needed, one that balances speed, quality and risk. By informing component choice, pinpointing flaws early in the software lifecycle and offering flexible remediation options, enterprises can better protect against malicious exploit, maintain developer productivity and avoid downstream rework costs."

For a complete view of the survey results and methodology used, visit: http://www.sonatype.com/people/2013/04/sonaty...ss-survey/ . To learn more about best practices for enabling developers to go fast and be secure, visit the Sonatype CLM product page: www.sonatype.com/clm .

About Sonatype Sonatype is leading the component revolution. The company's innovative Component Lifecycle Management (CLM) products enable organizations to realize the promise of agile, component-based software development while avoiding security, quality and licensing risks. Sonatype operates the Central Repository, the industry's primary source for open-source components, serving more than eight billion requests per year from more than 70,000 organizations. The company has been a pioneer in component-based software development since its founding by Jason van Zyl, the creator of the Apache Maven build management system and Sonatype's Central Repository. Since that time, Sonatype has been a leader in core open-source software development ecosystem projects used by more than nine million developers including Nexus, m2eclipse, and Hudson. Sonatype is privately held with investments from New Enterprise Associates (NEA), Accel Partners, Bay Partners, Hummer Winblad Venture Partners and Morgenthaler Ventures. Visit: www.sonatype.com or follow Sonatype on Twitter @Sonatype .

Apache, Apache Maven and Maven are trademarks of the Apache Software Foundation.

Media Contacts: April Harned PR for Sonatype Email Contact 646-246-0484

Scroll down for more posts ▼

Top 10 Most Recent News Articles

California Accelerates AI Law with Newsom's Bold Move

Updated Category News Views 3

Pushing AI Regulations into High Gear I'll tell you what—it's about time somebody shook things up in the AI world with more than empty promises. Governor Newsom's executive order is doing just that, fast-tracking the timeline for implementing California's SB 813. This move is like giving speed boots to the legislative process, revving up the rules to ensure AI doesn't...

Continue Reading
No Dogs Left Behind Marks Decade of Life-Saving Work

Updated Category News Views 4

A Decade of Dedication Some stories out there bring a much-needed shine to the otherwise relentless grind, and this is one of those rare gems. No Dogs Left Behind (NDLB) is celebrating a monumental milestone: ten years into their mission, they've crossed the incredible threshold of saving over 10,000 dogs from the clutches of slaughterhouses in East Asia. The nonprofit...

Continue Reading
Wounded Warrior Project Honors Veterans at Gala Dinner

Updated Category News Views 4

Wounded Warriors Gala: A Night of Heroic Honors In the swirling hum of Washington's gala scene, the Wounded Warrior Project (WWP) cuts through the noise with a sharp and poignant reminder of patriotism and community support. Their Courage Awards & Benefit Dinner®, pumped with the gravitas of corporate backing from the likes of Goldman Sachs, showcased a heartfelt...

Continue Reading
Sierra Ridge Advisors Join Gateway Financial Milestone

Updated Category News Views 5

Big Moves in the Financial Advisory World Let's dive right in. Here's a real shakeup in the advisory realm: 28 financial advisors and team members from Sierra Ridge Advisor Group are packing their bags for Gateway Financial Partners. We're talking about a significant shift involving $825 million in assets under advisement. Instead of sticking with Sierra Ridge as it...

Continue Reading
IRS Views Challenge Tax-Engineered Healthcare Schemes

Updated Category News Views 4

Nonprofit Models Shine Amid IRS Scrutiny Out in Oxnard, California, there's a brewing storm in the healthcare sector. No, it's not a billing error or yet another scandal. We're talking about a seismic shift that could poke holes in those tax-engineered Section 105(b) programs, all thanks to some hard-hitting IRS memoranda. The Nonprofit–TPA Model: A Safer Bet? Enter...

Continue Reading
Kobold Press Explores Roleplaying as Literacy Tool

Updated Category News Views 2

Gaming Illuminates Pathways to Literacy and Community Trust me, when an indie game publisher like Kobold Press makes waves, it's worth paying attention. They've carved a niche in the roleplaying world by marrying traditional game elements with valuable educational tools. The thrill of the game goes beyond rolling dice; it's a ticket to improving literacy, arithmetic, and...

Continue Reading
Crimson Coward's Cheez Nugs Shake Up Fast-Casual Scene

Updated Category News Views 7

New Kid on the Block: Cheez Nugs Buckle up folks, Crimson Coward is at it again. They're rolling out something they claim will blow your taste buds straight out of the water: Cheez Nugs. Dropping nationwide on September 18, 2026, these aren't your run-of-the-mill cheese bites. We're talking 100% whole-milk mozzarella, a golden herb-seasoned crust, and a mouthful of creamy...

Continue Reading
Chattanooga: A New Epicenter for Quantum Computing

Updated Category News Views 3

Quantum Leap: Chattanooga's Bold Move So Chattanooga’s making waves again, folks. EPB just unveiled its new big shot, the IonQ Forte Enterprise quantum computer. That's right, they’ve slapped a commercial quantum computer and a networking hub together, right here in this Tennessee city. Is this a tech haven or what? Not to mention, it’s the first in America. A New...

Continue Reading
Heafner Takes Helm at HGTC Amid Strategic Shifts

Updated Category News Views 2

A New Era for HGTC with Dr. Heafner at the Wheel Out of the frying pan and into the fire—Dr. Lori Heafner is stepping up to lead Horry-Georgetown Technical College (HGTC) with a clean slate and a hefty load of responsibility come January 2027. After enduring an intense national search by the Area Commission, she beat out tough competition to earn the role. It's not just...

Continue Reading
Digital Wine Atlas Maps 4.3 Million Vineyards Globally

Updated Category News Views 4

Revolutionizing Viticulture with Data In today's wild world, climate change isn't just shifting weather patterns—it's upending the age-old map of wine-making regions. We've got a new player on the field: the World Winery Map. It's digital, massive, and it’s shaking things up for winemakers and grape enthusiasts alike. This platform covers a staggering 4.3 million...

Continue Reading

Top 5 Most Recently Viewed Articles

B. Riley Files Lawsuit Against Former Investment Banking Head

Updated Category News Views 645

B. Riley Financial Inc Takes Legal Action B. Riley Financial Inc (NASDAQ: RILY) has recently embarked on a legal journey, alleging serious misconduct from its former investment banking head. The company claims that this individual, David Merriman, engaged in unprofessional actions to lure clients and team members to his new employer, Texas Capital Bank. This lawsuit was...

Continue Reading
Liquidia Corporation's Upcoming Financial Reporting and Insights

Updated Category News Views 129

Liquidia Corporation's Upcoming Financial Reporting Liquidia Corporation (NASDAQ: LQDA) has exciting updates on its financial performance. The company, known for its groundbreaking work in the biopharmaceutical sector, is set to release its first-quarter financial results soon. This announcement will be articulated in a live webcast scheduled for 8:30 a.m. Eastern Time on...

Continue Reading
Intraosseous Device Market Growth and Innovation Insights

Updated Category News Views 81

Intraosseous Devices Market Set for Robust Growth The intraosseous devices market is experiencing remarkable expansion, with projections suggesting sales will reach USD 938.6 million, a significant rise from USD 494.3 million in the near future. This represents a consistent compound annual growth rate (CAGR) of 5.8% between 2025 and 2035. This promising growth trajectory...

Continue Reading
Oncolytics Biotech's Pelareorep: Insights into Cancer Therapy Innovations

Updated Category News Views 119

Overview of the Oncology Market Landscape The oncology sector is evolving rapidly, projecting a revenue surge to almost US$900 billion globally, driven by a surge in cancer diagnoses and emerging therapeutic innovations. Despite facing regulatory hurdles, a wave of new entrants is working to change the way cancer is treated, promising alternate solutions for various...

Continue Reading
Investigation Notice Regarding Key Shareholders' Rights Issues

Updated Category News Views 197

Investigation into Shareholder Rights for Key Companies Halper Sadeh LLC, an advocate for investor rights, has launched an investigation concerning several prominent companies and their obligations to shareholders. This inquiry is crucial as it aims to ensure compliance with federal securities laws and ethical fiduciary duties. Air Transport Services Group, Inc. Overview...

Continue Reading