Are you still running old vulnerable open source code? You're not alone.

Sonatype released its 9th Annual State of the Software Supply Chain Report yesterday, highlighting several crucial trends and findings in open source software (OSS) and software supply chain security.

2023 witnessed an unprecedented surge of software supply chain attacks, recording twice as many incidents as the combined total from 2019-2022. Sonatype logged 245,032 malicious packages this year alone, indicating that one in eight open source downloads now pose known and avoidable risks. Despite the rise in attacks, the report highlights that a whopping 96% of vulnerabilities remain avoidable, mirroring the percentage from the previous year.

"96% of the time, there was already a fix available, which means, you know, only 4% of these problems are actually unavoidable," Brian Fox, co-founder and CTO at Sonatype commented during a LinkedIn live conversation about the report. "That's just a shocking statistic and it's really frustrating that it's largely unchanged in the last year."

Remember Log4j? It's still unpatched by many

Looking specifically at open source software, Sonatype found a particularly pernicious problem with a lack of patching, even when public patches were available.

One particular example, cited by Stephen Magill, VP of product innovation at Sonatype is that of the infamous Log4j open source project. Log4j is an open source logging component that is widely used by many applications and back in 2021 a particularly nasty set of vulnerabilities were publicly disclosed. Even though publicly available fully patched versions of Log4j have been around since 2021, in 2023 Sonatype is still seeing a large number of users and organizations downloading and using vulnerable versions of Log4j.

"We're closing in on about 22 months now post-Log4j and I looked when I was speaking at a conference two weeks ago, and 25% of the downloads of Log4j are of the known vulnerable versions," Magill said. "22 months later, that's shocking and frustrating."

A disconnect between perceived and actual security

Interestingly, the report found a significant disconnect between perceived security and reality in software development.

While 67% of survey respondents expressed confidence that their applications do not depend on known vulnerable libraries, nearly 10% reported security breaches due to open source vulnerabilities in the past year.

Furthermore, 39% of organizations discovered vulnerabilities within one to seven days, while over a third (36.2%) required over a week to mitigate these vulnerabilities. This gap in perceived and actual security poses a major challenge to organizations, urging them to reassess their vulnerability detection and mitigation strategies.

Optimal dependency management yields time and cost savings

With an overwhelming number of items for most organizations to patch, one of the keys to helping to improve security according to Sonatype is actually knowing what needs to be patched.

Not all vulnerabilities are exploitable and not all software updates are required by all application users. Sonatype's report found that teams using better software composition analysis software is helpful for organizations to determine what they actually have running and what might be at risk.

Sonatype's research found that proper software composition analysis can help organizations to determine optimal upgrade decisions, saving organizations a reasonable amount of time.