persistent-riskmaintenancelog4jfundingcorrosion

Sonatype — State of Software Supply Chain (10th)

Introduces the concept of 'Persistent Risk' and provides metrics for evaluating how organizational support and funding impact package security and maintenance velocity.

Summary

Sonatype defines 'Persistent Risk' as the combination of Unfixed Risk (identified vulnerabilities that remain unaddressed) and Corrosive Risk (delayed discovery of flaws in aging versions). While 95% of vulnerable downloaded releases already had a non-vulnerable version available, consumption behaviors remain stagnant, with 13% of Log4j downloads still targeting vulnerable versions nearly three years after the Log4Shell incident. Analysis shows that foundation-supported projects resolve vulnerabilities 264 days faster than independent projects and maintain code that is 10 'libyears' fresher. Furthermore, paid maintainers implement 55% more critical security and maintenance practices and resolve outstanding vulnerabilities 45% faster than their unpaid counterparts.

Related Checks

VULN_SLOW_REMEDIATION

The report finds that foundation-supported projects resolve security issues 264 days faster than their non-foundation counterparts.

Adverse Outcome

prolonged exposure to critical vulnerabilities due to the maintainer's lack of organizational resources

Because

fix-speed is a direct differentiator of project health, as demonstrated by the performance gap between foundation-supported and independent projects.

VULN_UNFIXED

Persistent risk is driven by the number of vulnerabilities identified but yet to be addressed, particularly those that have a fixed path forward (NPF) available.

Adverse Outcome

unnecessary exposure to exploits that have already been addressed in newer releases

Because

tracking unfixed vulnerabilities in the context of available fixes (NPF) identifies 'complacent' consumption behavior that accounts for 95% of vulnerable downloads.

Gaps Analysis

Evidence

Persistent Risk is new this year... defined using two primary factors: Unfixed and Corrosive Risk. Corrosive risk also incorporates the delay in discovering vulnerabilities in old versions.

Blind Spot

Risk Guard measures the presence of known vulnerabilities but doesn't calculate 'Corrosive Risk' based on the age of a version relative to its discovery date.

Actionable Capability

Risk Guard would be better if it calculated a 'Corrosion Score' that factored in both the number of unfixed CVEs and the time-to-remediate of the maintainer.

← Previous Next →