trendsmttrmalwaresbomretrospective

Sonatype - 10th Annual State of the Software Supply Chain 2024

Provides long-term trend data on the accelerating pace of open-source development and the corresponding breakdown in maintainer remediation capacity.

Summary

A 10-year retrospective of the software supply chain reveals a 1,466% increase in release frequency and 463% growth in CVEs between 2014-2023. More than 704,000 malicious packages have been discovered since 2019, doubling in volume in 2024 alone. Most critically, the mean time to remediate (MTTR) vulnerabilities has collapsed: while critical issues in 2017 were fixed in under 25 days, they now take an average of over 500 days in 2024. Despite 3x growth in SBOM publishing since 2022, adoption remains linear and far outpaced by the exponential growth of new components, leaving 95% of vulnerable downloads targeting versions that already have a fix available.

Related Checks

VULN_SLOW_REMEDIATION

The MTTR for critical vulnerabilities has ballooned from under 25 days in 2017 to over 500 days in 2024, showing a total breakdown in maintenance capacity.

Adverse Outcome

indefinite exposure to critical exploits due to a project's inability to maintain its dependency tree

Because

the dramatic upward trend in MTTR is the single most important indicator of a project's long-term security viability.

Gaps Analysis

Evidence

Mean time to remediate vulnerabilities is slowing significantly... critical issues in 2024 took over 500 days to fix, indicating response times for severe issues are worsening.

Blind Spot

Risk Guard uses current fix status but does not project 'Expected Time to Fix' based on a project's historical MTTR trends.

Actionable Capability

Risk Guard would be better if it provided an 'Estimated Remediation Window' for unpatched CVEs based on the maintainer's 3-year MTTR average.

← Previous Next →