[Skip to main content](#main-content)

The State of Software Supply Chain 2023

October 05, 2023

In 2023, twice as many software supply chain attacks took place as 2019-2022 combined, according to State of the Software Supply Chain Report from Sonatype.

Source: [Sonatype](https://www.sonatype.com)

Sonatype logged 245,032 malicious packages in 2023. One in eight open source downloads today pose known and avoidable risks.

Nearly all (96%) vulnerabilities are still avoidable. 2.1 billion OSS downloads with known vulnerabilities in 2023 could have been avoided because a better, fixed version was available — the exact same percentage as in 2022. For every suboptimal component upgrade made, there are typically 10 superior versions available.

Only 11% of open source projects are "actively maintained." Sonatype analyzed 1,176,407 open source projects across four major ecosystems and saw an 18% decline in "actively maintained" open source projects. The finding demonstrates the importance of constant vigilance from consumers in tracking the health of dependencies over time. The report highlights suboptimal open source consumption habits as the root cause of open source risk, contrary to public discourse often linking security risk with open source maintainers. In fact, the report demonstrates that maintainers, on average, promptly address and resolve issues.

"A lot of maintainers are very diligent — Big Tech companies go out of their way to hire talented people to maintain libraries they rely on," says Brian Fox, CTO at Sonatype. "Our industry needs to direct its efforts towards the right place. The fact that there's been a fix for almost all downloads of components with a known vulnerability tells us an immediate focus should be supporting developers on becoming better decision-makers, and giving them access to the right tools. The goal is to help developers be more intentional about downloading open source software from projects with the most maintainers and the healthiest ecosystem of contributors. This will not only create safer software, but also recoup nearly two weeks of wasted developer time each year."

Amidst rising software supply chain attacks, there's also a continued disconnect between perceived security and reality in software development:

■ Organizations think they have their software supply chains under control: 67% of respondents feel confident that their applications do not rely on known vulnerable libraries. Yet, nearly 10% of respondents reported their organizations had security breaches due to open source vulnerabilities in the last 12 months.

■ Awareness and mitigation of open source vulnerabilities lacks urgency in many organizations: The report found that 39% of organizations discover vulnerabilities within one to seven days; 29% take over a week to become aware and 28% discover within one day. When it comes to mitigation, 36.2% of respondents require over a week to mitigate vulnerabilities.

Developers play a pivotal role in driving progress, innovation, and excellence. Findings further highlight the direct relationship between developer productivity and access to superior tools and high-quality open source components. While investigating solutions for reducing security risks and time wasting, Sonatype discovered that:

■ Open source projects that are consistently maintained outperformed their counterparts on critical software security best practices. Compared to less-maintained libraries, consistently maintained projects tend to score:  
- 5.9x higher on SAST  
- 5.4x higher on Signed Releases  
- 5.1x higher on Dependency Update Tools  
- 3.6x higher on Code Review  
- 3.8x higher on Branch Protection

■ Optimal dependency management saves time, money, and decreases security risk: When teams use better security data that reduce false positive findings by 25%, in combination with making optimal upgrade decisions, each team saves a total 1.5 months of time, per application, per year. This equates to a 2X boost in time saved over just making optimal upgrades.

"Impactful change necessitates clear direction," adds Fox. "For both better and worse, today's software organizations face an overwhelming amount of options for addressing these issues — from a multitude of frameworks to weekly governmental guidance, and more. All that choice is ripe to create paralysis, making it hard to get started."

Among the spike in software supply chain vulnerabilities, there are signs of developers taking measures to improve efficiencies and security posture. The report shows the use of AI/ML components in software development surging by 135% in less than a year, largely owing to the massive efficiencies the technology affords software developers, in addition to how quickly AI/ML components can be integrated into software development workflows. That said, developers and organizations face significant challenges in developing their own AI products.

"While AI/ML technology has become more accessible than ever, there are still significant implementation challenges. Developers and data scientists have to choose from hundreds of thousands of options for models and libraries," says Stephen Magill, Vice President of Innovation at Sonatype. "Choosing open source solutions comes with all of the familiar requirements around managing open source security risk. Choosing proprietary solutions can come with high costs. And in both cases, licensing of both the models and the model outputs can be very uncertain."

## Related Links

[www.sonatype.com](https://www.sonatype.com)

## Industry News

[Moderne Expands Agent Tools Platform with Python Support](/moderne-expands-agent-tools-platform-with-python-support)

February 19, 2026

Moderne announced Python language support across its Agent Tools platform, expanding the infrastructure organizations use to build code intelligence and safely coordinate large-scale software change across enterprise environments.

[Kong Partners with Solace](/kong-partners-with-solace)

February 19, 2026

Kong Inc. announced that Solace has joined Kong's Premium Technology Partner Program.

[Slack Releases Real-Time Search (RTS) API and Model Context Protocol (MCP) Server](/slack-releases-real-time-search-rts-api-and-model-context-protocol-mcp-server)

February 18, 2026

Slack announced the general availability of Real-Time Search (RTS) API and Model Context Protocol (MCP) Server.

[Quesma Releases BinaryAudit](/quesma-releases-binaryaudit)

February 17, 2026

Quesma announced BinaryAudit, the independent benchmark testing whether AI can find hidden threats in software binaries before they cause damage.

[GitLab Transcend Showcases How Intelligent Orchestration Helps Accelerate Innovation Velocity Across the Software Lifecycle](/gitlab-transcend-showcases-how-intelligent-orchestration-helps-accelerate-innovation-velocity-across)

February 12, 2026

[GitLab](https://gitlab.com/) hosted GitLab Transcend, an exclusive virtual event for technology leaders highlighting the true potential of agentic AI for software delivery.

[Black Duck Expands Polaris Integrations](/black-duck-expands-polaris-integrations)

February 12, 2026

Black Duck announced the immediate availability of a set of enhanced Black Duck Polaris Platform integrations across all major source code management (SCM) platforms — including GitHub, GitLab, Azure DevOps, and Bitbucket.

[Infragistics Ultimate 25.2 Released](/infragistics-ultimate-252-released)

February 12, 2026

App Builder, the low-code platform from Infragistics that streamlines app creation from design to code, announced the expansion of its App Builder AI capabilities as part of the launch of Infragistics Ultimate 25.2, the company's flagship UX and UI product.

[SPARKHUB Releases Vibeland](/sparkhub-releases-vibeland)

February 12, 2026

SPARKHUB PTE. LTD. officially launched Vibeland, a one-click deployment platform designed specifically for Gemini/Google AI Studio vibe coding scenarios, helping users rapidly transform AI-generated code into accessible, shareable online products.

[Keycard Acquires Anchor.dev](/keycard-acquires-anchordev)

February 12, 2026

Keycard has acquired Anchor.dev to extend its platform to govern coding agents.

[SmartBear Partners with Carahsoft](/smartbear-partners-with-carahsoft)

February 11, 2026

SmartBear and Carahsoft Technology Corp. announced an expanded partnership that makes it easier for Federal, State and Local agencies to deliver quality, compliant software.

[Backslash Security Raises $19M Series A to Secure Vibe Coding Boom in the Enterprise](/backslash-security-raises-19m-series-a-to-secure-vibe-coding-boom-in-the-enterprise)

February 10, 2026

[Backslash Security](https://www.backslash.security) announced a $19 million Series A funding round led by KOMPAS VC, with participation from Maniv, Artofin Venture Capital, and existing investors StageOne Ventures and First Rays Capital.

[Kong Launches Context Mesh](/kong-launches-context-mesh)

February 10, 2026

Kong announced Kong Context Mesh, a product that can automatically discover enterprise APIs, transform them into agent-consumable tooling, and deploy those tools with runtime governance.

[Guardsquare Acquires Verimatrix XTD](/guardsquare-acquires-verimatrix-xtd)

February 09, 2026

Guardsquare completed the acquisition of the Extended Threat Defense (XTD) technology and assets from Verimatrix, advancing its mobile app security platform for mobile developers and enterprises worldwide.

[Perforce AI Products and Features Achieve ISO 42001 Certification](/perforce-ai-products-and-features-achieve-iso-42001-certification)

February 09, 2026

Perforce Software announced that several AI products and features within its portfolio obtained ISO 42001 certification, the first international standard that specifically validates an organization’s responsible management of Artificial Intelligence (AI).

[GitHub Brings Anthropic Claude and OpenAI Codex to Agent HQ](/github-brings-anthropic-claude-and-openai-codex-to-agent-hq)

February 05, 2026

GitHub announced the availability of Anthropic's Claude agent and OpenAI Codex on GitHub and VS Code, now in public preview.

[More Industry News](industry-news)

## Email signup

[Sign up for DEVOPSdigest Email](https://zc.vg/hJSA5)

## Upcoming Webinars

[AppSec at Scale: Actionable Insights from 1,000+ Cyber Range Events](https://www.brighttalk.com/webcast/20800/661323?utm_source=devopsdigest&utm_medium=referral&utm_campaign=webinar_appsec-cyberrange)

February 24, 2026

[How to Cut API Testing Time With AI-Powered Automation](https://www.parasoft.com/webinar/demo-with-live-qa-parasoft-continuous-quality-suite/)

March 04, 2026

[C & C++ Continuous Testing](https://hubs.la/Q03SZfRD0)

March 18, 2026

[C & C++ Software Testing](https://www.parasoft.com/webinar/demo-with-qa-parasoft-c-and-c-software-testing/)

April 15, 2026

## On-Demand Webinars

[GitLab Transcend: Exploring the True Potential of Agentic AI for Software Delivery](https://about.gitlab.com/events/transcend/virtual/?utm_medium=sponsorship&utm_source=devopsdigest&utm_campaign=eg_amer_comm_owned-event_ai_en_transcend_virtual)

[Choosing AI-Powered API Testing Tools: What Capabilities Really Matter](https://www.brighttalk.com/webcast/18694/661747?bt_tok=%7B%7Bcontact.BT_fastpass_token%7D%7D&utm_source=Parasoft&utm_medium=brighttalk&utm_campaign=661747)

[Automated C/C++ Testing Roadmap for AI Safety & ISO/PAS 8800](https://www.brighttalk.com/webcast/18694/660659?bt_tok=%7B%7Bcontact.BT_fastpass_token%7D%7D&utm_source=Parasoft&utm_medium=brighttalk&utm_campaign=660659)

[AI in Software Testing: What's Real. What's Hype. What Actually Helps in 2026](https://hubs.la/Q03_ZFDx0)

[See How Fast AI Can Build Your Virtual Test Environment](https://www.devopsdigest.com/simpleads/redirect/14096)

[AI-Enhanced Roadmap to Code Quality & Compliance](https://www.brighttalk.com/webcast/18694/658419?bt_tok=&utm_source=Parasoft&utm_medium=brighttalk&utm_campaign=658419)

[Securing the AI Transformation in a Hyperconnected World](https://www.checkpoint.com/securing-ai-virtual-event-2025/)

[Too Many Tests, Too Little Time: Smarter Ways to Tackle Manual Regression Testing](https://www.brighttalk.com/webcast/18694/657146?bt_tok=&utm_source=Parasoft)

[The Gaps in AI-Powered Testing and What's Still Manual](https://www.parasoft.com/webinar/the-gaps-in-ai-powered-testing/?utm_campaign=27532150-DevOps%20Digest%20Webinar%202025&utm_source=Webinar%20DevOpsDigest%20Forrester&utm_medium=Post%20DevOpsDigest&utm_content=Webinar%20Link%20Forrester)

[AI in DevOps: Transforming the Developer Experience and Expanding the Security Perimeter](https://info.enterprisemanagement.com/ai-in-devops-webinar-devopsdigest)

[See How Fast AI Can Build Your Virtual Test Environment](https://www.devopsdigest.com/simpleads/redirect/13880)

[AppSec Redefined: A New Way Forward](https://info.securityjourney.com/appsec-redefined-a-new-way-forward-webinar?utm_campaign=17098919-%5B3rd%20Party%5D%20DevOpsDigest&utm_source=DevOpsDigest&utm_medium=consyn&utm_content=a%20new%20way%20forward%20webinar)

[Measuring the ROI of Secure Coding Training](https://info.securityjourney.com/measuring-the-roi-of-secure-coding-training-webinar?utm_campaign=17098919-%5B3rd%20Party%5D%20DevOpsDigest&utm_source=DevOpsDigest&utm_medium=consyn&utm_content=measuring-roi-webinar)

[How Are You Solving The Developer Security Knowledge Gap?](https://info.securityjourney.com/how-are-you-solving-the-developer-security-knowledge-gap?utm_campaign=17098919-%5B3rd%20Party%5D%20DevOpsDigest&utm_source=DevOpsDigest&utm_medium=consyn&utm_content=solving-the-knowledge-gap-webinar)

[From Code to Culture: Driving Developer Engagement in Security Initiatives](https://info.securityjourney.com/from-code-to-culture-driving-developer-engagement-in-security-initiatives?utm_campaign=17098919-%5B3rd%20Party%5D%20DevOpsDigest&utm_source=DevOpsDigest&utm_medium=consyn&utm_content=from-code-to-culture-webinar)

[All Webinars ...](/webinars)

## Analyst Reports

[2025 Gartner® Magic Quadrant™ for Email Security](https://engage.checkpoint.com/2025-gartner-magic-quadrant-for-email-security)

[2025 Gartner® Magic Quadrant™ for AI Code Assistants](https://about.gitlab.com/gartner-mq-ai-code-assistants/?utm_medium=sponsorship&utm_source=devopsdigest&utm_campaign=eg_amer_comm_x_x_en_gartnermgai)

[2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall](https://engage.checkpoint.com/2025-gartner-magic-quadrant-for-hybrid-mesh-firewalls)

[2025 GigaOm Radar for Anti-Phishing](https://engage.checkpoint.com/2025-gigaom-radar-for-anti-phishing-report)

[The Forrester Wave: Zero Trust Platforms, Q3 2025](https://engage.checkpoint.com/2025-forrester-wave-report-for-zero-trust-platforms)

[GigaOm 2025 Enterprise Firewalls Radar](https://engage.checkpoint.com/2025-gigaom-radar-enterprise-firewall-report)

[Miercom 2025 Enterprise and Hybrid Mesh Firewall Security Report](https://www.checkpoint.com/2025-miercom-firewall-report/)

[GigaOm 2025 Attack Surface Management Radar](https://engage.checkpoint.com/2025-gigaom-attack-surface-management-radar)

[GigaOm Radar for Cloud Workload Security](https://www.checkpoint.com/resources/items/report-gigaom-radar-for-cloud-workload-security-q1-2025)

[GigaOm Radar for Cloud Network Security](https://www.checkpoint.com/resources/items/report-gigaom-radar-for-cloud-network-security-q4-2024)

[GigaOm Radar for Web Application Firewall (WAF) & API Security](https://www.checkpoint.com/resources/items/report-gigaom-radar-for-application-and-api-security-q4-2024)

[2024 Gartner® Magic Quadrant™ for Email Security Platforms](https://emailsecurity.checkpoint.com/resources/reports/2024-gartner-magic-quadrant)

[GigaOm Radar Report for Cloud-Native Application Protection Platforms (CNAPPs)](https://www.checkpoint.com/press-releases/check-point-software-is-a-leader-in-gigaom-cloud-radar-paving-the-way-in-cloud-security-innovation-delivering-advanced-threat-prevention-and-scalability/)

[Forrester Wave™: Enterprise Firewall Solutions, Q4 2024](https://engage.checkpoint.com/2024-forrester-wave-enterprise-firewall-solutions-report)

[2024 Gartner® Magic Quadrant™ for Endpoint Protection Platforms](https://engage.checkpoint.com/2024-gartner-magic-quadrant-for-endpoint-protection-platforms-report)

[All Analyst Reports ...](/analyst-reports)

## White Papers

[The Intelligent Software Development Era](https://about.gitlab.com/developer-survey/)

[Cyber Security Report 2026](https://www.checkpoint.com/security-report/)

[GoogleTest Adoption Challenges for Safety-Critical Code](https://hubs.ly/Q03S_HYZ0)

[Guide to API Security](https://hubs.la/Q03MwTY-0)

[How to Maximize Functional Testing Productivity With AI and a Lean Web UI Test Strategy](https://hubs.la/Q03MwQzg0)

[Performance Testing Best Practices Guide](https://hubs.la/Q03MwMhX0)

[The Essential Guide to Environment-Based Testing](https://hubs.la/Q03MwHtC0)

[The Economics of Software Innovation](https://www.devopsdigest.com/simpleads/redirect/13773)

[6 Questions You Should Be Asking About Product Security Guide](https://info.securityjourney.com/6-questions-about-product-security?utm_campaign=17098919-%5B3rd%20Party%5D%20DevOpsDigest&utm_source=DevOpsDigest&utm_content=6-questions-product-security-guide)

[Seven Steps to an Ideal Secure Coding Training Program Guide](https://info.securityjourney.com/seven-steps-to-an-ideal-secure-coding-training-program?utm_campaign=17098919-%5B3rd%20Party%5D%20DevOpsDigest&utm_source=DevOpsDigest&utm_medium=consyn&utm_content=7-steps-training-program-guide)

[Six Steps to Meet Compliance and Shift Your Culture Guide](https://info.securityjourney.com/six-steps-to-meet-compliance?utm_campaign=17098919-%5B3rd%20Party%5D%20DevOpsDigest&utm_source=DevOpsDigest&utm_medium=consyn&utm_content=6-steps-compliance-guide)

[Cybersecurity Education vs. Awareness](https://info.securityjourney.com/education-vs-awareness-roundtable?utm_campaign=17098919-%5B3rd%20Party%5D%20DevOpsDigest&utm_source=DevOpsDigest&utm_medium=consyn&utm_content=education-vs-awareness-ebook)

[Zoom Selects Security Journey to Drive Application Security Excellence](https://www.securityjourney.com/case-study-zoom?utm_campaign=17098919-%5B3rd%20Party%5D%20DevOpsDigest&utm_source=DevOpsDigest&utm_medium=consyn&utm_content=Zoom-Case-Study)

[Tactical AppSec: A Champions' Field Guide](https://info.securityjourney.com/tactical-appsec-field-guide?utm_campaign=17098919-%5B3rd%20Party%5D%20DevOpsDigest&utm_source=DevOpsDigest&utm_medium=consyn&utm_content=security-champion-field-guide)

[WAF Comparison Project - A Real-World Comparison](https://www.devopsdigest.com/simpleads/redirect/13662)

[All White Papers ...](/white-papers)

## Media Partners

[Global RSS Feed](global-feed)

## User login

## The Latest

[Kubernetes Established as De Facto "Operating System" for AI](/kubernetes-established-as-de-facto-operating-system-for-ai)

February 20, 2026

[Securing LLM Applications Means Rethinking How We Trust Systems](/securing-llm-applications-means-rethinking-how-we-trust-systems)

February 19, 2026

[Application Security in the Age of AI](/application-security-in-the-age-of-ai)

February 18, 2026

[The AI Paradox: How Innovation Is Outpacing Security in Modern Software Development](/the-ai-paradox-how-innovation-is-outpacing-security-in-modern-software-development)

February 17, 2026

[Why Graph-Based Retrieval Is Becoming Essential for Reliable LLM Applications](/why-graph-based-retrieval-is-becoming-essential-for-reliable-llm-applications)

February 13, 2026

[4th-Party Risk: How Commercial Software Puts You At Risk](/4th-party-risk-how-commercial-software-puts-you-at-risk)

February 12, 2026

[Operating Systems and the Miracle of Standardization](/operating-systems-and-the-miracle-of-standardization)

February 11, 2026

[Trust and Compliance in the Age of AI: Navigating the Risks of Intelligent Software Development](/trust-and-compliance-in-the-age-of-ai-navigating-the-risks-of-intelligent-software-development)

February 10, 2026

[The Enterprise AI Integration Challenge: How Intelligent Orchestration Drives Business Outcomes](/the-enterprise-ai-integration-challenge-how-intelligent-orchestration-drives-business-outcomes)

February 09, 2026

[Global Cyber Security Attacks Reach Record Levels as AI Accelerates Threat Landscape](/global-cyber-security-attacks-reach-record-levels-as-ai-accelerates-threat-landscape)

February 06, 2026

[Measuring What Matters: Balancing Data, Trust and Alignment for Developer Productivity](/measuring-what-matters-balancing-data-trust-and-alignment-for-developer-productivity)

February 05, 2026

[To Migrate or Not To Migrate? Why Enterprises Are Reconsidering "Rip and Replace'" DevOps Migrations](/to-migrate-or-not-to-migrate-why-enterprises-are-reconsidering-rip-and-replace-devops-migrations)

February 04, 2026

[Why Data's Value Isn't About Where It Lives - But How It's Used](/why-datas-value-isnt-about-where-it-lives-but-how-its-used)

February 03, 2026

[Easing Engineer Burnout with a Unified Approach to Identity](/easing-engineer-burnout-with-a-unified-approach-to-identity)

February 02, 2026

[Why Model Choice Still Matters in Voice AI](/why-model-choice-still-matters-in-voice-ai)

January 30, 2026

[Empowered DevOps Teams Move Fast: Why Local Leadership Beats Command and Control](/empowered-devops-teams-move-fast-why-local-leadership-beats-command-and-control)

January 29, 2026

[Rethinking Application Security Testing Investments in the Era of AI-Generated Code](/rethinking-application-security-testing-investments-in-the-era-of-ai-generated-code)

January 28, 2026

[What npm Must Do Now to Reduce Malware Risk in Its Repository](/what-npm-must-do-now-to-reduce-malware-risk-in-its-repository)

January 27, 2026

[2026: When AI Becomes Mission-Critical for Regulated Industries](/2026-when-ai-becomes-mission-critical-for-regulated-industries)

January 26, 2026

[From Automation to Intelligence: How AI Will Redefine DevOps in 2026](/from-automation-to-intelligence-how-ai-will-redefine-devops-in-2026)

January 23, 2026

## Hot Topics

* [Agile](/hot-topic/agile)
* [AI/ML](/hot-topic/aiml)
* [AIOps](/hot-topic/aiops)
* [Analytics](/hot-topic/analytics)
* [API](/hot-topic/api)
* [APM](/hot-topic/apm)
* [Automation](/hot-topic/automation)
* [BizDevOps](/hot-topic/bizdevops)
* [CI/CD](/hot-topic/cicd)
* [Cloud](/hot-topic/cloud)
* [Cloud-Native](/hot-topic/cloud-native)
* [Containers/K8s](/hot-topic/containersk8s)
* [Database](/hot-topic/database)
* [Dev Culture](/hot-topic/dev-culture)
* [Development](/hot-topic/development)
* [DevEx](/hot-topic/devex)
* [DevOps](/hot-topic/devops)
* [DevSecOps](/hot-topic/devsecops)
* [Digital Transformation](/hot-topic/digital-transformation)
* [E-Commerce](/hot-topic/e-commerce)
* [IaC](/hot-topic/iac)
* [Low-Code/No-Code](/hot-topic/low-codeno-code)
* [Mainframe](/hot-topic/mainframe)
* [MLOps](/hot-topic/mlops)
* [Mobile](/hot-topic/mobile)
* [Monitoring](/hot-topic/monitoring)
* [Open Source](/hot-topic/open-source)
* [Platform Engineering](/hot-topic/platform-engineering)
* [Remote Work](/hot-topic/remote-work)
* [Serverless](/hot-topic/serverless)
* [Testing/Quality](/hot-topic/testingquality)
* [Vibe Coding](/hot-topic/vibe-coding)
* [VSM](/hot-topic/vsm)