logo

BlackDuck-Open-Source-Risk-Analysis-Report-2026.md

ID: 102f499b-0cc0-459a-af46-3f40a9123893

STIX ID: report--102f499b-0cc0-459a-af46-3f40a9123893

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2026-04-05

Last Modified Date: 2026-04-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The 2026 Open Source Security and Risk Analysis (OSSRA) report from Black Duck analyzes nearly 3,000 projects across 947 codebases and documents dramatic growth in open source usage and risk: mean vulnerabilities per codebase more than doubled (to 581), 65% of organizations reported a supply chain attack in 2025, license conflicts surged to historic highs (68% of codebases), and widespread maintenance debt and AI-assisted development have accelerated the attack surface; the report concludes with governance, SBOM, and tool-integration recommendations to manage these systemic risks.