Benchmarks organizational security maturity and identifies third-party code as the primary driver of critical security debt.
Veracode's 15th State of Software Security report, analyzing 1.3 million applications, reveals a 327% increase in average flaw fix times over the last 15 years, rising from 171 days to 252 days. Currently, 50% of organizations carry 'critical security debt,' defined as high-severity flaws left unresolved for more than a year, with a majority stemming from third-party code and the software supply chain. Leading organizations are distinguished by resolving over 10% of flaws monthly and keeping open-source critical debt under 15%, while lagging organizations take over a year to fix half of their flaws and carry 100% of their critical debt in open-source components.
The report highlights a growing gap where lagging organizations take longer than a year to remediate even half of discovered flaws.
persistent exposure to known vulnerabilities that remain unpatched for extended periods
benchmarking a project's fix speed against industry standards identifies maintainers who are failing to keep pace with the volume of discovered security debt.
50% of organizations carry critical security debt consisting of accumulated flaws left open for longer than a year.
inclusion of packages with long-standing, unresolved security vulnerabilities
tracking unfixed vulnerabilities directly measures the primary component of security debt identified in the software supply chain.
Leading organizations keep open-source critical debt under 15%, while 100% of critical debt is open source in lagging organizations.
Risk Guard does not currently calculate an organizational 'Security Debt' metric across all scanned dependencies.
Risk Guard would be better if it provided a 'Security Debt' score that quantified the total volume and age of unfixed vulnerabilities across a project's entire transitive dependency graph.