Benchmarks the current state of DevSecOps maturity and identifies 'SLA exhaustion' and 'AI overconfidence' as emerging supply chain risks.
The 2024 State of Open Source report reveals a plateau in DevSecOps maturity: 52% of teams fail to meet vulnerability remediation SLAs, largely due to 74% setting unrealistic targets of one week or less. Supply chain security remains elusive, with 45% of organizations forced to replace vulnerable build components within the last year. While SBOM monitoring (62%) is growing, other critical practices like pipeline security (50%) and regular audits (25%) lag behind. Furthermore, a concerning 84% of developers apply the same level of scrutiny to AI-suggested open-source packages as human-suggested ones, despite AI's known tendency to introduce or hallucinate vulnerabilities.
Over half of teams (52%) fail to meet their vulnerability remediation SLAs, even as they set increasingly aggressive deadlines.
accumulating security debt and extended windows of exposure to known critical vulnerabilities
measuring remediation speed against organizational SLAs is a key indicator of whether a security team is keeping pace with its own risk policies.
84% say they apply the same level of scrutiny to AI-suggested open source packages as they would human-suggested ones... nearly 80% believe AI coding tools generate more secure code.
Risk Guard does not detect if a dependency was introduced by an AI coding assistant, which has a different risk profile for 'hallucinated' or insecure package suggestions.
Risk Guard would be better if it could flag packages that are known to be 'hallucinated' by LLMs or frequently suggested by AI assistants without being widely used in the community.