SBN

Introducing our 2020 State of the Software Supply Chain Report

An analysis of high performance open source development practices

“If we move faster, we can’t be as secure.”

“If we build in more security, we can’t be as fast.”

For years, development and security pros have argued that effective risk management practices are always at the expense of developer productivity, or that a faster release velocity can be achieved but only when security practices don’t weigh it down.

Our 2020 State of the Software Supply Chain Report delivers new evidence that faster innovation and better risk management do not have to be mutually exclusive – in fact, they actually feed off of each other. High Performance engineering teams are now accelerating velocity while simultaneously improving security outcomes. Even better? Developers in High Performance teams demonstrate higher levels of job satisfaction.” You can read more about our analysis of these four practice clusters in Chapter 4 of the report.

high performers SSC

In addition to the above, the 2020 State of Software Supply Chain Report, now in its sixth year,  analyzes data from over 1.5 trillion open source download requests, 24,000 open source projects, and 5,600 enterprise development teams.  Here’s more of what you can expect from year six:

  • We dive into a 430% increase in next-generation software supply chain attacks since last year’s report (see Chapter 1)
  • We shed light on download requests for 1 trillion npm and 376 billion java components (see Chapter 2)
  • We discuss how the best OSS projects are updating dependencies 530x faster than their peers and how this practice positively impact security (see Chapter 3)
  • We compare high performing development teams to low performers to reveal 26x faster remediation of open source Vulnerabilities (see Chapter 4)
  • We analyze over 1700 applications to reveal that 11% of OSS components used to assemble applications have (Read more...)

*** This is a Security Bloggers Network syndicated blog from Sonatype Blog authored by Derek Weeks. Read the original post at: https://blog.sonatype.com/2020-state-of-the-software-supply-chain-report

Secure Guardrails