{"id":32626,"date":"2017-07-21T08:40:31","date_gmt":"2017-07-21T12:40:31","guid":{"rendered":"http:\/\/www.opensource.im\/uncategorized\/software-wet-wipes-sonatype-advocates-supply-chain-hygiene-computerweekly-com-blog.php"},"modified":"2017-07-21T08:40:31","modified_gmt":"2017-07-21T12:40:31","slug":"software-wet-wipes-sonatype-advocates-supply-chain-hygiene-computerweekly-com-blog","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/open-source-software\/software-wet-wipes-sonatype-advocates-supply-chain-hygiene-computerweekly-com-blog.php","title":{"rendered":"Software wet wipes, Sonatype advocates supply chain hygiene &#8211; ComputerWeekly.com (blog)"},"content":{"rendered":"<p><p>    Supply chain automation company Sonatype produces what it calls    itsSoftware Supply Chain Report every year (now in its    third) in an attempt tohighlights alleged risks lurking    within open source software components.  <\/p>\n<p>        Access the latest thinking in AI and machine learning, and        look at how these technologies could help your IT        department      <\/p>\n<p>            By submitting your personal information, you agree that            TechTarget and its partners may contact you regarding            relevant content, products and special offers.          <\/p>\n<p>              You also agree that your personal information may be              transferred and processed in the United States, and              that you have read and agree to the Terms of Use and the Privacy Policy.            <\/p>\n<p>    The firm gets quite puritanical and says it wants to quantify    the empirical benefits of actively managing so-called software    supply chain hygiene.  <\/p>\n<p>    Theres a big claim being made here and it reads as follows     organisations that are actively managing the quality of open    source components flowing into production applications are    realising:  <\/p>\n<p>    Sonatype specialises in technology areas which    includeautomated governance tools within the context of    what we now understand to be the DevOps discipline.  <\/p>\n<p>    With the above fact (and perhaps a pinch of salt) in mind then,    we can learn that analysis of more than 17,000 applications    reveals that applications built by teams utilising automated    governance tools reduced the percentage of defective components    by 63%.  <\/p>\n<p>      Companies are no longer building software      applications from scratch, they are manufacturing them as fast as they can using an infinite      supply of open source component parts. However, many still      rely on manual and time consuming governance and security      practices instead of embracing DevOps-native automation. Our      research continues to show that development teams managing      trusted software supply chains are dramatically improving      quality and productivity, said Wayne Jackson, CEO,      Sonatype.    <\/p>\n<p>    The wider claims here (from Sonatype) include    suggestions that even when vulnerabilities are known, open    source software projects are slow to remediate  if they do so    at all. Only 15.8 percent of OSS projects actively fix    vulnerabilities, and even then the mean time to remediation was    233 days.  <\/p>\n<p>    This says the firm puts the onus on DevOps    organisations to actively govern which opens source OSS    projects they work with, and which components they ultimately    consume.  <\/p>\n<p>    The full report is available here.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Originally posted here:<br \/>\n<a target=\"_blank\" href=\"http:\/\/www.computerweekly.com\/blog\/Open-Source-Insider\/Software-wet-wipes-Sonatype-advocates-supply-chain-hygiene\" title=\"Software wet wipes, Sonatype advocates supply chain hygiene - ComputerWeekly.com (blog)\">Software wet wipes, Sonatype advocates supply chain hygiene - ComputerWeekly.com (blog)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Supply chain automation company Sonatype produces what it calls itsSoftware Supply Chain Report every year (now in its third) in an attempt tohighlights alleged risks lurking within open source software components. Access the latest thinking in AI and machine learning, and look at how these technologies could help your IT department By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-32626","post","type-post","status-publish","format-standard","hentry","category-open-source-software"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/32626"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=32626"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/32626\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=32626"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=32626"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=32626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}