# AppSec / DevOps Survey: 63% Concerned With Open Source

**February 05, 2014**  
By [Derek Weeks](/content/blog/author/derek-weeks/index.html)

1 minute read time

A sneak peek at interim results from the "Developers and Application Security: Who is Responsible?" 2014 survey are in, and there's still [time for you to participate](https://www.surveymonkey.com/s/Developers_and_AppSec). Here's a little something for you to think about.

Once upon a time, we used to develop our own software. But these days, we are developing [90% of our applications from open source](https://www.linuxfoundation.org/blog/blog/a-summary-of-census-ii-open-source-software-application-libraries-the-world-depends-on) software (OSS) components. With the need for speed (to market) pressuring development organizations, coupled with the convenience of OSS, the days of "write your own code" are gone forever – and that is good news.

The bad news: there are no "free puppies" in open source. While OSS benefits are tremendous, they do come with responsibilities we cannot overlook. The ease of downloading pre-built components should not distract us from our responsibilities to be vigilant about their quality, security, and licensing.

Early results from a Trusted Software Alliance survey of 225+ [DevOps](/content/resources/articles/what-is-devops/index.html) and [AppSec](/content/resources/articles/what-is-application-security/index.html) professionals show that vigilance around OSS security concerns is top-of-mind. Where functional defects rank as the top security concern, 63% of those surveyed ranked open source vulnerabilities second.

Got 5 minutes? [You can take the survey now](https://www.surveymonkey.com/s/Developers_and_AppSec). Then, you can share the results with your colleagues to spark conversation, highlight a critical need, or compare how your practices rank among your peers.

Written by **Derek Weeks**  
Derek serves as vice president and DevOps advocate at Sonatype and is the co-founder of All Day DevOps, an online community of 65,000 IT professionals.
