Open Source Security Management Neglected by Most Software Developers

Free Webinar hosted by WhiteSource to Offer Tips and Strategies to Resolve the Issue

Open source has become a popular way to build software products, but security issues that accompany its widespread use are not sufficiently addressed. Rami Sass, CEO of WhiteSource, will host a free webinar, “Keeping a Closer Eye on Open Source: How and Why,” on December 18, 2013 at 9:30 a.m. (PST).

A recent WhiteSource study of 2,944 software projects with open source components found that 23% had security vulnerabilities. 85% used outdated open source libraries. A software security report by Veracode showed that 70% of applications fail to comply with basic enterprise security policies.

“As open source software becomes mainstream it requires the same level of security and reliability as proprietary software,” said Dan Yachin, Research Director at IDC’s Emerging Technologies group. “Organizations must therefore implement processes and solutions to promptly identify and fix vulnerabilities in their open source software. At the very least, they should be able to upgrade to a new version of an open source library when a vulnerability is discovered and fixed by the community,” he added.

Small and medium-size companies often lack the manpower and resources to build internal open source management systems. But the security risks of open source can’t be ignored.

“SMBs too often avoid the issue of open source management because of cost and effort, but the problem doesn’t go away and there’s an equal security risk factor for any size enterprise,” said Rami Sass, CEO of WhiteSource. “Sometimes SMBs use Excel spreadsheets because they’re low-cost, but it doesn’t take care of the security problem,” he added.

WhiteSource offers development teams a user-friendly SaaS platform for managing open source components. The WhiteSource platform is seamlessly weaved into the development management process, saving valuable time and effort.

The webinar agenda will include:

  • Open source security vulnerabilities and key statistics
  • Tracking and updating open source inventory down to the last dependency
  • How to be notified about security vulnerabilities and bug fixes
  • How to deploy an effective open source governance program
Your Open Source Libraries: Identifying Hidden Dangers -

About Mend.io

Mend.io offers the first AI native application security platform, empowering organizations to build and run a proactive AppSec program tuned for AI powered development. The unified platform secures AI generated code and embedded AI components, drives risk reduction through AI powered remediation, automates compliance, and provides a holistic enterprise scale view of risks and clear actions for developers across your entire codebase.