Open Source Security Management Neglected by Most Software Developers
Free Webinar hosted by WhiteSource to Offer Tips and Strategies to Resolve the Issue
Open source has become a popular way to build software products, but security issues that accompany its widespread use are not sufficiently addressed. Rami Sass, CEO of WhiteSource, will host a free webinar, โKeeping a Closer Eye on Open Source: How and Why,โ on December 18, 2013 at 9:30 a.m. (PST).
A recentย WhiteSource studyย of 2,944 software projects with open source components found that 23% had security vulnerabilities. 85% used outdated open source libraries. A software security report by Veracode showed that 70% of applications fail to comply with basic enterprise security policies.
โAs open source software becomes mainstream it requires the same level of security and reliability as proprietary software,โ said Dan Yachin, Research Director at IDCโs Emerging Technologies group. โOrganizations must therefore implement processes and solutions to promptly identify and fix vulnerabilities in their open source software. At the very least, they should be able to upgrade to a new version of an open source library when a vulnerability is discovered and fixed by the community,โ he added.
Small and medium-size companies often lack the manpower and resources to build internal open source management systems. But theย security risks of open sourceย canโt be ignored.
โSMBs too often avoid the issue of open source management because of cost and effort, but the problem doesnโt go away and thereโs an equal security risk factor for any size enterprise,โ said Rami Sass, CEO of WhiteSource. โSometimes SMBs use Excel spreadsheets because theyโre low-cost, but it doesnโt take care of the security problem,โ he added.
WhiteSource offers development teams a user-friendly SaaS platform for managing open source components. The WhiteSource platform is seamlessly weaved into the development management process, saving valuable time and effort.
The webinar agenda will include:
- Open source security vulnerabilities and key statistics
- Tracking and updating open source inventory down to the last dependency
- How to be notified about security vulnerabilities and bug fixes
- How to deploy an effective open source governance program
About Mend.io
Mend.io is a leading application security solution that helps organizations fix less and reduce risk faster. Built for both AI-driven and modern development workflows, Mend.io gives teams visibility into all code โ human-written, AI-generated, open source, third-party and container components โ and helps them prioritize and remediate the risks that matter most.