Accessibility Statement Skip Navigation
  • Back to Global Sites
  • +972-77-2005042
  • Blog
  • Journalists
  • GDPR
  • Send a Release
PR Newswire: news distribution, targeting and monitoring
  • News
  • Products
  • Contact
  • Hamburger menu
  • PR Newswire: news distribution, targeting and monitoring
  • Send a Release
    • Telephone

    • +972-77-2005042 from 8 AM - 11 PM IL

    • Contact
    • Contact

      +972-77-2005042
      from 8 AM - 11 PM IL

  • When typing in this field, a list of search results will appear and be automatically updated as you type.

  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR
  • Request More Information
  • Journalists
  • GDPR

WhiteSource Report Reveals Security is Developers' Top Concern Related to Open Source Usage

WhiteSource releases report to shed light on current open source challenges and best practices for improving open source security management

WhiteSource_Logo

News provided by

WhiteSource

27 Sep, 2018, 15:00 IDT

Share this article

Share toX

Share this article

Share toX

TEL AVIV, Israel, Sept. 27, 2018 /PRNewswire/ -- WhiteSource, the leader in open source security and license compliance management, announced today its first annual report on Open Source Security Vulnerability Management. The report findings, based on a survey of 650 developers from the US and Western Europe, and an analysis of the largest database of aggregated open source vulnerabilities, reveal that open source vulnerabilities have become the number one challenge for developers when working with open source components.

The survey results reveal that developers rated security as their top concern when dealing with open source components, above integration and functionality. What's more, a developer invests an average of 15 hours a month dealing with open source security vulnerabilities, but only a small fraction of that time (25%) is devoted to actual remediation.

Research results also showed that Effective Usage Analysis, WhiteSource's technology for prioritizing open source vulnerabilities based on their analyzed effectiveness, helped beta customers reduce the number of effective open source security vulnerabilities alerts by a substantial 85%, saving organizations a monthly average of 10 hours per developer.

Bruno Lavit, Senior release engineer at ForgeRock, participated in the beta testing and found the results very promising: "Effective Usage Analysis gives us the added value of faster remediation, with trace analysis that pinpoints the exact location of vulnerable dependencies." Lavit added "This new capability enables us to significantly cut down on the time our developers spend dealing with open source vulnerability alerts."

The full 2018 State of Open Source Vulnerability Management Report is available at https://www.whitesourcesoftware.com/open-source-vulnerability-management-report/.

Additional key findings in the report:

  • Open source security vulnerabilities are on the rise: The data shows a significant 60% rise in the number of open source security vulnerabilities in 2017. This finding presents a serious challenge to development and security teams striving to meet security objectives.
  • Developers are not managing open source vulnerabilities efficiently: Developers spend a lot of time addressing open source vulnerabilities, but the absence of standard practices and lack of developer‑focused tools result in an inefficient use of time.
  • Prioritization is key to effective open source vulnerability management: Following a solid prioritization strategy for open source vulnerability remediation will save development teams time and money, and ensure they address the most critical issues first.

"Our findings show a sharp increase in the number of reported vulnerabilities in open source projects, which is taking a toll on developers who rely heavily on these components," said David Habusha, VP Product at WhiteSource. "The research clearly shows that development teams cannot handle the influx of open source vulnerabilities and prioritization strategies and tools are becoming a necessity in order to properly secure applications."

About WhiteSource

WhiteSource is the leader in continuous open source security and license compliance management. Its vision is to empower businesses to develop better software by harnessing the power of open source. Industry leaders like Microsoft, IBM, and hundreds more trust WhiteSource to secure and manage the open source components in their software. The WhiteSource solution has been recognized by Forrester as the best current offering in their Software Composition Analysis (SCA) Wave™ report in 2017. For more information, please visit www.whitesourcesoftware.com.

Media Contact
Head of Communications
Gabriel Avner
[email protected]

SOURCE WhiteSource

Related Links

http://www.whitesourcesoftware.com

Modal title

Contact PR Newswire

  • +972-77-2005042
    from 8 AM - 11 PM IL

Global Sites

  • APAC
  • APAC - Traditional Chinese
  • Asia
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany

 

  • India
  • Indonesia
  • Israel
  • Italy
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland

 

  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921
Global Sites
  • Asia
  • Brazil
  • Canada
  • Csezh
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Israel
  • Italie
  • Mexico
  • Middle East
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • United States
+972-77-2005042
from 8 AM - 11 PM IL
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • Cookie Settings
Copyright © 2026 Cision US Inc.