BlackDuck-Open-Source-Risk-Analysis-Report-2026.md
ID: 102f499b-0cc0-459a-af46-3f40a9123893
STIX ID: report--102f499b-0cc0-459a-af46-3f40a9123893
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2026-04-05
Last Modified Date: 2026-04-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The 2026 Open Source Security and Risk Analysis (OSSRA) report from Black Duck analyzes nearly 3,000 projects across 947 codebases and documents dramatic growth in open source usage and risk: mean vulnerabilities per codebase more than doubled (to 581), 65% of organizations reported a supply chain attack in 2025, license conflicts surged to historic highs (68% of codebases), and widespread maintenance debt and AI-assisted development have accelerated the attack surface; the report concludes with governance, SBOM, and tool-integration recommendations to manage these systemic risks.
