Highlights the massive scale of outdated software and the 'transitive dependency' problem that masks visibility and compliance risks.
Audits of nearly 1,000 commercial applications reveal that open-source software is universal, appearing in 97% of codebases. However, 86% of applications contain open-source vulnerabilities, and 81% harbor high-risk or critical vulnerabilities—with jQuery components alone accounting for 8 of the top 10 high-risk flaws. Transitive dependencies make up 64% of open-source components and are responsible for nearly 30% of all license conflicts. Maintenance is a significant challenge: 91% of applications contain outdated open-source components, and 90% are more than 10 versions behind the current release, indicating a widespread failure to manage the lifecycle of third-party dependencies.
33% of audited applications had open-source components with no license or a customized license, creating severe legal and compliance risks.
legal liability and inability to distribute software due to unlicensed third-party code
the high prevalence of unlicensed code in commercial applications validates the critical need for automated license detection.
56% of all audited applications had license conflicts, with nearly 30% of those conflicts originating from transitive dependencies.
copyright infringement and violation of redistribution terms in commercial products
license conflicts are a pervasive risk in complex dependency trees, making automated compliance checking essential for commercial software integrity.
64% of these open-source components were transitive dependencies... Nearly 30% of component license conflicts found in our audits were caused by transitive dependencies.
Risk Guard evaluates direct dependencies but often lacks deep visibility into the 'Transitive License Risk' that manifests deep in the stack.
Risk Guard would be better if it provided a 'Full-Stack License Map' that tracked and flagged license incompatibilities across the entire transitive dependency tree.