Mitigating Open Source Persistent Risks in Software Security

The Evolution of Open Source Risk: Persistent Challenges in Software Security

October 30, 2024
By Aaron Linskens

4 minute read time

Mitigating Open Source Persistent Risks in Software Security

As organizations increasingly rely on open source software, associated security risks grow, demanding more robust and proactive risk management.

Our 2024 State of the Software Supply Chain report dives into these and other emerging challenges, particularly focusing on the concept of "Persistent Risk" — a term highlighting unresolved vulnerabilities and contamination risks within software supply chains.

Let's explore a few insights from the report to better understand the evolution of open source risk and its associated security challenges.

Understanding Persistent Risk: A Dual Threat

"Persistent Risk" in open source software is a unique category of risk shaped by prolonged exposure to unresolved vulnerabilities.

We defined this concept based on our observations that ongoing, unresolved threats in software can degrade its security integrity over time.

Persistent Risk encompasses two main factors:

Unfixed and Corrosive Risk create Persistent Risk, like rust on metal — the longer vulnerabilities go unaddressed, the more they grow, leading to a decline in software resilience and increased vulnerability to breaches. This underscores the urgency for timely identification and resolution to prevent long-term security issues.

The 2024 report reveals a critical truth: components with Persistent Risk degrade over time, increasing the chance of systemic failures. Importantly, 95% of downloaded vulnerable components had a fix available, highlighting the need for proactive management.

Factors Influencing Persistent Risk

Three primary behaviors drive Persistent Risk within organizations:

The Role of Open Source Consumption: Balancing Quality and Risk

Open source consumption practices, more than the inherent quality of the components, play a significant role in Persistent Risk.

While quality remains a priority, our report found that proactive measures, such as using software bills of materials (SBOMs) and dependency management tools, are essential for maintaining a secure software supply chain.

Additionally, the Open Source Security Foundation (OpenSSF) Scorecard serves as a valuable tool in evaluating the responsiveness and quality of open source projects, offering developers insights into project stability and security practices.

Evolving Best Practices for Managing Open Source Risk

As open source usage scales, so must the sophistication of risk management strategies.

Best practices highlighted by the report for mitigating Persistent Risk include:

Building Resilience Against Persistent Risk

Addressing Persistent Risk proactively not only preserves software integrity, but also builds resilience against escalating software supply chain threats.

To learn more about the state of open source and how to protect your software supply chain, check out the full State of the Software Supply Chain report.

Written by Aaron Linskens

Aaron is a technical writer at Sonatype. He works at a crossroads of technical writing, developer advocacy, and information design. He aims to get developers and non-technical collaborators to work better together in solving problems and building software.