Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Endor Labs’ ‘State of Dependency Management 2023’ Report Offers Insight on Explosive Popularity of AI and LLMs—and How They Impact Application Security

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Ron Harnik
Word Count
789
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

Endor Labs has released the "State of Dependency Management 2023" report, which highlights emerging trends and challenges in software security, particularly in the use of open source software (OSS) and large language models (LLMs). The report underscores the popularity of ChatGPT’s API and the inability of current LLM-based AI platforms to reliably classify malware risk, as they succeed in only 5% of cases. It also reveals that nearly half of all applications do not call security-sensitive APIs, a figure that drops drastically when dependencies are considered. Despite the widespread use of open source components, applications utilize only a small fraction of the imported code, and vulnerabilities in unused code are rarely exploitable. The report suggests that organizations should document their software components and vulnerabilities using a Software Bill of Materials (SBOM) to improve security and productivity. Endor Labs emphasizes the importance of understanding how components are used within applications to better assess risks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.