TOP HIGHLIGHTS
& BENCHMARKS
Derek E. Weeks
VP and DevOps Advocate
RESEARCH COVERED BY
DevOps Leadership Series & Contributing Author
Upcoming Speaking Engagements:
LISA15 | USENIX (Nov. 12, 2015 - DC)
OWASP NYC CyberSocial (September 16, 2015 - NYC)
Atlanta Java Users Group (Sept. 15, 2015 - Atlanta)
HP Protect (Sept. 3, 2015 - DC)
@weekstweets
@sonatype
@sonatype
106,000Organizations Analyzed
Source: 2015 State of the Software Supply Chain Report
@sonatype
We all have a
SOFTWARE
SUPPLY CHAIN
@sonatype
Modern software development HAS
CHANGED
Our process
HASN’T CHANGED
ENOUGH
@sonatype
John Willis
DevOps Days Core Organizer
Gareth Rushgrove
Puppet Labs
Nigel Simpson
F-100 Entertainment Giant
@sonatype
201320122011200920082007 2010
2B1B500M 4B 6B 8B 13B 17B
2014
Source: 2015 State of the Software Supply Chain Report
@sonatype
Open Source Download Requests…
POLLING QUESTION
What percent of modern apps are
composed of open source components?
10
a. 10 - 20%
b. 50 - 60%
c. 80 - 90%
How Dependent on 3rd Parties Are We?
10% Custom Written Code
Typical Application
Open Source
Cloud Services
Closed Source
90% From 3rd Parties
@sonatype
Better and
fewer
suppliers
Higher
quality
parts
Improved
visibility
and
traceability
3 savings in
modern supply chains Automation
@sonatype
@sonatype
CHANGE
Typical component is
updated 3 - 4X per year.
985,000 OSS COMPONENTS
11 MILLION OSS USERS108,000 SUPPLIERS
Source: 2015 State of the Software Supply Chain Report
@sonatype
POLLING QUESTION
How many open source suppliers do
companies work with?
15
a. 5,372
b. 7,601
c. 15,118
Suppliers Serving Manufacturers
Source: 2015 State of the Software Supply Chain Report
Orders
(downloads)
Suppliers
(artifacts)
Parts
(versions)
Average 240,757 7,601 18,614
@sonatype
41%
390 days (median 265
days). CVSS 10s 224 days
59%
never repaired
<7
The best were
remediated in under a
week.
Source: USENIX, https://www.usenix.org/system/files/login/articles/15_geer_0.pdf
@sonatype
@sonatype
Source: modulecounts.com
@sonatype
Sample of
Open Source
Repositories
2014
Volume of
Download Requests
Central.sonatype.org 17,213,084,947
Npmjs.org 15,460,748,856
NuGetGallery.com 280,124,916
Bintray.com 250,000,000
Source: 2015 State of the Software Supply Chain Report
@sonatype
CHANGE
Typical component is
updated 3 - 4X per year.
Unlike COTS, there is no clear, effective
COMMUNICATION
channel
…but there can be.
985,000 OSS COMPONENTS
11 MILLION OSS USERS
@sonatype
Repository Managers Accessing the Central Repository
Source: 2015 State of the Software Supply Chain Report
@sonatype
Source: 2015 State of the Software Supply Chain Report
Public
Repos
Local
Repo
Build
Tool
Public
Repos
Build
Tool
PATTERN #1
PATTERN #2
@sonatype
POLLING QUESTION
What percent of components are
sourced from public repositories?
24
a. 25%
b. 55%
c. 95%
Source: 2015 State of the Software Supply Chain Report
Public
Repos
Local
Repo
Build
Tool
Public
Repos
Build
Tool
95%
of downloads
5%
of downloads
@sonatype
26
100-200
Cycle Time: Minutes-Hours
@sonatype
Source: 2015 State of the Software Supply Chain Report
240,000Components Downloaded Annually
@sonatype
POLLING QUESTION
What percent of organizations do not
have a policy governing quality and
integrity of components?
29
a. 25%
b. 55%
c. 95%
Q: Does your organization have an open source policy?
Half of organizations continue to run without an open source policy.
Source: 2012, 2013, 2014 Sonatype Open Source Development and Application Security Survey
@sonatype
If it does not fit,
it does not get done.
@sonatype
Orders Quality Control
Average
downloads
# with known
vulnerabilities
% with known
vulnerabilities
% known
vulnerabilities
(2013 or older)
240,757 15,337 7.5% 66.3%
Download Volumes of Old CVEs
Source: 2015 State of the Software Supply Chain Report
@sonatype
Source: 2015 State of the Software Supply Chain Report
Outdated Versions Downloaded
@sonatype
Image Source: caranddriver.com
@sonatype
@sonatype
@sonatype
Analysis of 1,500+ Applications
106
components
24
known
vulnerabilities
9
restrictive
licenses
@sonatype
v
1
2
3
Create a software Bill of
Materials for one application
Design a frictionless, automated,
“continuous” approach
Empower developers with the
right information at the right time
@sonatype
CHECK THE QUALITY AND INTEGRITY OF EVERY BUILD
Jenkins integration run
history and status of each
build, across multiple
applications.
Builds might be stable or
unstable. Also shows build
success and failures.
Nexus Lifecycle policy
violations and
vulnerabilities levels are
displayed within the
Jenkins CI dashboard.
@sonatype
Shift Left= ZTTR (Zero Time to Remediation)
Analyze all components
from within your IDE
License, Security and Architecture data for each
component, evaluated against your policy
EMPOWER DEVELOPERS FROM THE START
@sonatype
CREATE A SOFTWARE BILL OF MATERIALS
bit.ly/softwareBOM
5MINUTES
@sonatype
YOU ALL GET A COPY
TODAY!
IT’S TIME WE IMPROVE OUR
SOFTWARE SUPPLY CHAINS

More Related Content

PPTX
Accelerating Innovation with Software Supply Chain Management
PPTX
A "Firewall" for Bad Binaries
PPTX
Continuous Acceleration with a Software Supply Chain Approach
PDF
Risks in the Software Supply Chain
PPTX
Accelerating innovation with software supply chain management
PDF
The Legend of Software Hollow: Defeating the Headless Horseman of Faulty Appl...
PDF
Software supply chain management: Gaining velocity without losing control
PPTX
The Illusion of Control: Seven Deadly Wastes in Your Devops Practice
Accelerating Innovation with Software Supply Chain Management
A "Firewall" for Bad Binaries
Continuous Acceleration with a Software Supply Chain Approach
Risks in the Software Supply Chain
Accelerating innovation with software supply chain management
The Legend of Software Hollow: Defeating the Headless Horseman of Faulty Appl...
Software supply chain management: Gaining velocity without losing control
The Illusion of Control: Seven Deadly Wastes in Your Devops Practice

What's hot (20)

PPTX
Shifting the conversation from active interception to proactive neutralization
PPTX
DevSecOps - It can change your life (cycle)
PDF
No Devops Without Continuous Testing
PDF
ABC's of Service Virtualization
PPT
Introducing: Klocwork Insight Pro | November 2009
PDF
Driving Risks Out of Embedded Automotive Software
PDF
AppsSec In a DevOps World
PPTX
5 Things Every CISO Needs To Know About Open Source Security - A WhiteSource ...
PDF
Find Out What's New With WhiteSource September 2018- A WhiteSource Webinar
PDF
EuroSPI 2016 - Software Safety and Security Through Standards
PPTX
DevSecOps-OWASP Indonesia Day 2017
PPTX
Mentors View: Aligning Your Team and Your Powers for Success
PPTX
Empowering Application Security Protection in the World of DevOps
PDF
Better Governance Banking on Continuous Delivery
PDF
Rx for FDA Software Compliance
PPTX
Find Out What's New With WhiteSource May 2018- A WhiteSource Webinar
PDF
The DevOps Challenge: Open Source Security at Scale
PDF
10 Things You Might Not Know: Continuous Integration
PDF
Winning open source vulnerabilities without loosing your deveopers - Azure De...
PPTX
The Evolving Role of the Developer in 2021
Shifting the conversation from active interception to proactive neutralization
DevSecOps - It can change your life (cycle)
No Devops Without Continuous Testing
ABC's of Service Virtualization
Introducing: Klocwork Insight Pro | November 2009
Driving Risks Out of Embedded Automotive Software
AppsSec In a DevOps World
5 Things Every CISO Needs To Know About Open Source Security - A WhiteSource ...
Find Out What's New With WhiteSource September 2018- A WhiteSource Webinar
EuroSPI 2016 - Software Safety and Security Through Standards
DevSecOps-OWASP Indonesia Day 2017
Mentors View: Aligning Your Team and Your Powers for Success
Empowering Application Security Protection in the World of DevOps
Better Governance Banking on Continuous Delivery
Rx for FDA Software Compliance
Find Out What's New With WhiteSource May 2018- A WhiteSource Webinar
The DevOps Challenge: Open Source Security at Scale
10 Things You Might Not Know: Continuous Integration
Winning open source vulnerabilities without loosing your deveopers - Azure De...
The Evolving Role of the Developer in 2021
Ad

Similar to Findings Revealed: 2015 State of the Software Supply Chain (20)

PPTX
Webinar: "Sicurezza e qualità del software: un viaggio attraverso vulnerabili...
PDF
Hidden Speed Bumps on the Road to "Continuous"
PDF
Sonatype's 2013 OSS Software Survey
PDF
CloudBees and Sonatype - MeetUp
PPTX
2019 04-18 -DevSecOps-software supply chain
PDF
JUC Europe 2015: Making Strides towards Enterprise-Scale DevOps...with Jenkin...
PPTX
7 Reasons Your Applications are Attractive to Adversaries
PPTX
Dev Secops Software Supply Chain
PPTX
Nadog dev secops_survey
PPTX
Webinar: "Il software: la strategia vincente sta nella qualità"
PPTX
Live 2014 Survey Results: Open Source Development and Application Security Su...
PDF
2024 Trends in Software Supply Chain Security
PDF
Webinar: "La supply chain del software vista a raggi X"
PPTX
Security Software Supply Chains - Sonatype - DevSecCon Singapore March 2019
PDF
DevSecCon Singapore 2019: Embracing Security - A changing DevOps landscape
PDF
White Paper: Software Supply Chain Automation: Going Beyond Agile, Lean and D...
PDF
Open Source Adoption in the Enterprise
PDF
Open Source 360° Survey Key Takeaways
PPTX
Aligning Your Team and Your Powers for Success
PPTX
The DevOps Tool Kit: Building the Software Supply Chain
Webinar: "Sicurezza e qualità del software: un viaggio attraverso vulnerabili...
Hidden Speed Bumps on the Road to "Continuous"
Sonatype's 2013 OSS Software Survey
CloudBees and Sonatype - MeetUp
2019 04-18 -DevSecOps-software supply chain
JUC Europe 2015: Making Strides towards Enterprise-Scale DevOps...with Jenkin...
7 Reasons Your Applications are Attractive to Adversaries
Dev Secops Software Supply Chain
Nadog dev secops_survey
Webinar: "Il software: la strategia vincente sta nella qualità"
Live 2014 Survey Results: Open Source Development and Application Security Su...
2024 Trends in Software Supply Chain Security
Webinar: "La supply chain del software vista a raggi X"
Security Software Supply Chains - Sonatype - DevSecCon Singapore March 2019
DevSecCon Singapore 2019: Embracing Security - A changing DevOps landscape
White Paper: Software Supply Chain Automation: Going Beyond Agile, Lean and D...
Open Source Adoption in the Enterprise
Open Source 360° Survey Key Takeaways
Aligning Your Team and Your Powers for Success
The DevOps Tool Kit: Building the Software Supply Chain
Ad

More from Sonatype (20)

PPTX
DevOps Days Columbus - Derek Weeks - 2019
PDF
2019 DevSecOps Reference Architectures
PDF
RSAC DevSecOpsDays 2018 - We are all Equifax
PPTX
DevSecOps reference architectures 2018
PDF
30+ Nexus Integrations to Accelerate DevOps
PDF
2017 DevSecOps Survey
PPTX
Starting and Scaling DevOps In the Enterprise
PPTX
DevOps Friendly Doc Publishing for APIs & Microservices
PDF
The Unrealized Role of Monitoring & Alerting w/ Jason Hand
PPTX
DevOps and All the Continuouses w/ Helen Beal
PDF
Serverless and the Way Forward
PDF
A Small Association's Journey to DevOps w/ Edward Ruiz
PDF
What's My Security Policy Doing to My Help Desk w/ Chris Swan
PDF
Characterizing and Contrasting Kuhn-tey-ner Awr-kuh-streyt-ors
PDF
Static Analysis For Security and DevOps Happiness w/ Justin Collins
PDF
Automated Infrastructure Security: Monitoring using FOSS
PDF
System Hardening Using Ansible
PDF
There is No Server: Immutable Infrastructure and Serverless Architecture
PDF
Getting out of the Job Jungle with Jenkins
PDF
Modern Infrastructure Automation
DevOps Days Columbus - Derek Weeks - 2019
2019 DevSecOps Reference Architectures
RSAC DevSecOpsDays 2018 - We are all Equifax
DevSecOps reference architectures 2018
30+ Nexus Integrations to Accelerate DevOps
2017 DevSecOps Survey
Starting and Scaling DevOps In the Enterprise
DevOps Friendly Doc Publishing for APIs & Microservices
The Unrealized Role of Monitoring & Alerting w/ Jason Hand
DevOps and All the Continuouses w/ Helen Beal
Serverless and the Way Forward
A Small Association's Journey to DevOps w/ Edward Ruiz
What's My Security Policy Doing to My Help Desk w/ Chris Swan
Characterizing and Contrasting Kuhn-tey-ner Awr-kuh-streyt-ors
Static Analysis For Security and DevOps Happiness w/ Justin Collins
Automated Infrastructure Security: Monitoring using FOSS
System Hardening Using Ansible
There is No Server: Immutable Infrastructure and Serverless Architecture
Getting out of the Job Jungle with Jenkins
Modern Infrastructure Automation

Recently uploaded (20)

PDF
Designing Intelligence for the Shop Floor.pdf
PDF
DuckDuckGo Private Browser Premium APK for Android Crack Latest 2025
PPTX
Cybersecurity: Protecting the Digital World
PDF
AI-Powered Threat Modeling: The Future of Cybersecurity by Arun Kumar Elengov...
PDF
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency
PPTX
WiFi Honeypot Detecscfddssdffsedfseztor.pptx
PDF
Microsoft Office 365 Crack Download Free
PPTX
assetexplorer- product-overview - presentation
PDF
How AI/LLM recommend to you ? GDG meetup 16 Aug by Fariman Guliev
PDF
Wondershare Recoverit Full Crack New Version (Latest 2025)
DOCX
Modern SharePoint Intranet Templates That Boost Employee Engagement in 2025.docx
PPTX
Monitoring Stack: Grafana, Loki & Promtail
PPTX
Advanced SystemCare Ultimate Crack + Portable (2025)
PDF
Topaz Photo AI Crack New Download (Latest 2025)
PPTX
Why Generative AI is the Future of Content, Code & Creativity?
PDF
Types of Token_ From Utility to Security.pdf
PPTX
"Secure File Sharing Solutions on AWS".pptx
PDF
Top 10 Software Development Trends to Watch in 2025 🚀.pdf
PDF
Autodesk AutoCAD Crack Free Download 2025
PDF
The Dynamic Duo Transforming Financial Accounting Systems Through Modern Expe...
Designing Intelligence for the Shop Floor.pdf
DuckDuckGo Private Browser Premium APK for Android Crack Latest 2025
Cybersecurity: Protecting the Digital World
AI-Powered Threat Modeling: The Future of Cybersecurity by Arun Kumar Elengov...
Product Update: Alluxio AI 3.7 Now with Sub-Millisecond Latency
WiFi Honeypot Detecscfddssdffsedfseztor.pptx
Microsoft Office 365 Crack Download Free
assetexplorer- product-overview - presentation
How AI/LLM recommend to you ? GDG meetup 16 Aug by Fariman Guliev
Wondershare Recoverit Full Crack New Version (Latest 2025)
Modern SharePoint Intranet Templates That Boost Employee Engagement in 2025.docx
Monitoring Stack: Grafana, Loki & Promtail
Advanced SystemCare Ultimate Crack + Portable (2025)
Topaz Photo AI Crack New Download (Latest 2025)
Why Generative AI is the Future of Content, Code & Creativity?
Types of Token_ From Utility to Security.pdf
"Secure File Sharing Solutions on AWS".pptx
Top 10 Software Development Trends to Watch in 2025 🚀.pdf
Autodesk AutoCAD Crack Free Download 2025
The Dynamic Duo Transforming Financial Accounting Systems Through Modern Expe...

Findings Revealed: 2015 State of the Software Supply Chain

Editor's Notes

  • #8: We are in the business of open source governance, management and compliance (add in slide or on cover slide) Your Company Runs on Software – it must be trusted
  • #15: The suppliers and the manufacturers need to share information. And right now that communication channel is not only broken, it simply doesn’t exist. Components are updated an average of 4X a year to fix issues, but how do the manufacturers even learn about it? …….. Supply chain management at Toyota was transformational. They went from being a textile company to the world’s leading automobile manufacturer, largely because of these improvements and these principles. And even today, the effect of their philosophy is pretty remarkable to me. For example, Toyota-wide, they have 226 suppliers. General Motors has 5,500. And so imagine the efficiencies of only having to deal with 226 suppliers as opposed to 5,000. And what’s further to that, is that GM produces 54% of the content of their vehicles and Toyota produces 27%. So, GM has 1/20th the suppliers, and yet they produce half of the content of their vehicles. And so it’s no surprise that a Volt costs $40,000 and a Prius $20,000. And the Prius sells 20,000 units a month and GM sells 1,700.
  • #22: The suppliers and the manufacturers need to share information. And right now that communication channel is not only broken, it simply doesn’t exist. Components are updated an average of 4X a year to fix issues, but how do the manufacturers even learn about it? …….. Supply chain management at Toyota was transformational. They went from being a textile company to the world’s leading automobile manufacturer, largely because of these improvements and these principles. And even today, the effect of their philosophy is pretty remarkable to me. For example, Toyota-wide, they have 226 suppliers. General Motors has 5,500. And so imagine the efficiencies of only having to deal with 226 suppliers as opposed to 5,000. And what’s further to that, is that GM produces 54% of the content of their vehicles and Toyota produces 27%. So, GM has 1/20th the suppliers, and yet they produce half of the content of their vehicles. And so it’s no surprise that a Volt costs $40,000 and a Prius $20,000. And the Prius sells 20,000 units a month and GM sells 1,700.
  • #28: Cycle Time Squeeze Work Arounds Batch Scans Rework Exposure
  • #32: Cycle Time Squeeze Work Arounds Batch Scans Rework Exposure
  • #42: First of all… when you can clearly see the threat levels of components in your IDE, you can easily shift to a safer one. The area here in the lower right works like a slider… you simply slide to the right to identify a safer, accepted version of a component. So you see, you not only see a potential problem early one, but you also see the solution. Better yet… ========= Click onto pane and zoom in and zoom out Guide your eyes to the RIGHT…. This is a normal Developer IDE called Eclipse… Sonatype made a PLUGIN within it to show a developer the component BEFORE before they choose or commit to ELECTIVE/AVOIDABLE Risk/AttackSurface/Complexity/LegalIssues … The RED chain (e.g.) is every version of Strut2-core…. And if you move RIGHT far enough…. It will lack KNOW CRITICAL vulnerabilities. The Green bar charts are the download popularity… which doesn’t speak at all to SECURITY… but may give people more comfort that it is stable and being used. License rsik is based on self-defined policy – we track if the use of this license can cause your whole website to now be FREE common opensource – like GPL… which might be very bad for you… and a DIFFERENT type of risk…
  • #44: When do you have an hour to spare?