BOSTON, April 13, 2022 — Tidelift, a leading provider of solutions for improving the health and security of the open source behind modern applications, today released the 2022 Open Source Software Supply Chain Survey Report, providing critical insights into the state and practice of open source software supply chain management.
This comprehensive study of nearly 700 technologists, now in its fourth year, explored the most urgent challenges development teams face when building applications with open source. It also reveals new insights into how confident technologists are in their organizations’ current open source management practices, and in the open source components and languages they use more generally. Further it highlights how organizations are employing emerging open source management best practices, including the use of software bills of materials (SBOMs) and repositories of approved open source components.
“Open source is now the de facto standard application development platform and is a proven driver of business success and innovation. Yet as its popularity grows, the challenge of helping development teams manage open source health and security becomes exponentially more difficult,” said Donald Fischer, chief executive officer, Tidelift. “This year’s survey data demonstrates that organizations are beginning to better understand both the challenges stopping them from gaining full benefit from open source and the management best practices that will help them overcome those challenges.”
Key findings:
Security is technologists’ most urgent challenge, while complying with government requirements is a rising concern for large organizations.
Only 15% of organizations are extremely confident in their open source management practices; the majority have some concerns about keeping open source up-to-date, secure, and well-maintained.
Getting approval to use new open source components in large organizations is often slow and tedious.
Only 37% of organizations are aware of new government software supply chain security requirements around security and SBOMs.
Many organizations are already using or piloting the best practice of building centralized repositories of approved open source components.
Receive a copy of the full survey report here.
About Tidelift:
Tidelift helps organizations effectively manage the open source behind modern applications. Through the Tidelift Subscription, the company delivers the tools, data, and strategies powering an inclusive and organization-wide approach to improving the health and security of the open source software supply chain. Tidelift enables organizations to move fast and stay safe when building applications with open source, so they can create more incredible software, even faster. https://tidelift.com/
Contact:
Kristen Wiltse
KW Communications
978-578-4047
kwiltse@comcast.net