Company
Date Published
Author
Alyssa Miller
Word count
668
Language
English
Hacker News points
None

Summary

The State of Open Source Security Survey - 2020` is an annual report by Snyk that analyzes trends in open source security and how organizations manage vulnerabilities in their software and cloud native technologies. The report, which has been produced annually since 2017, aims to better understand the challenges faced by the community through a survey and gather data from various sources. In the 2020 report, Snyk plans to expand its focus on cloud native technologies such as containers, orchestration tools, and infrastructure as code. The previous year's report found that known vulnerabilities grew by almost 88% across multiple ecosystems between 2017 and 2018, with PHP seeing a significant increase in reported vulnerabilities in 2018. Additionally, the time to fix vulnerabilities ranged from 289 days to over 2,000 days for popular packages in npm. The 2020 report aims to build upon these findings while expanding its scope to understand how organizations are driving their DevSecOps culture and managing security across open source software, containers, and orchestration.