Introduces the concept of 'Persistent Risk' and provides metrics for evaluating how organizational support and funding impact package security and maintenance velocity.
Sonatype defines 'Persistent Risk' as the combination of Unfixed Risk (identified vulnerabilities that remain unaddressed) and Corrosive Risk (delayed discovery of flaws in aging versions). While 95% of vulnerable downloaded releases already had a non-vulnerable version available, consumption behaviors remain stagnant, with 13% of Log4j downloads still targeting vulnerable versions nearly three years after the Log4Shell incident. Analysis shows that foundation-supported projects resolve vulnerabilities 264 days faster than independent projects and maintain code that is 10 'libyears' fresher. Furthermore, paid maintainers implement 55% more critical security and maintenance practices and resolve outstanding vulnerabilities 45% faster than their unpaid counterparts.
The report finds that foundation-supported projects resolve security issues 264 days faster than their non-foundation counterparts.
prolonged exposure to critical vulnerabilities due to the maintainer's lack of organizational resources
fix-speed is a direct differentiator of project health, as demonstrated by the performance gap between foundation-supported and independent projects.
Persistent risk is driven by the number of vulnerabilities identified but yet to be addressed, particularly those that have a fixed path forward (NPF) available.
unnecessary exposure to exploits that have already been addressed in newer releases
tracking unfixed vulnerabilities in the context of available fixes (NPF) identifies 'complacent' consumption behavior that accounts for 95% of vulnerable downloads.
Persistent Risk is new this year... defined using two primary factors: Unfixed and Corrosive Risk. Corrosive risk also incorporates the delay in discovering vulnerabilities in old versions.
Risk Guard measures the presence of known vulnerabilities but doesn't calculate 'Corrosive Risk' based on the age of a version relative to its discovery date.
Risk Guard would be better if it calculated a 'Corrosion Score' that factored in both the number of unfixed CVEs and the time-to-remediate of the maintainer.