Black Duck

70 stats7 reports

All Statistics

48% of development teams experience bottlenecks in code rework related to AI-generated code.

Software DevelopmentCode QualityAI-Generated CodeAI Coding Assistants

Teams with full governance for AI coding assistants in place are 55% more likely to report a major improvement in efficiency.

AI Coding GovernanceSoftware DevelopmentAI Coding Assistants

64% of development teams express moderate or extreme concern about AI coding assistants introducing security defects or vulnerabilities.

Security VulnerabilitiesRisk ManagementAI-Generated CodeAI Coding AssistantsCode Quality

98% of codebases contain open source components.

Open SourceOpen Source Security

Mean vulnerabilities per codebase increased by 107% year-over-year.

VulnerabilitiesOpen Source Security

Open source component counts increased by 30% year-over-year.

Open SourceDependency ManagementOpen Source Security

76% of organizations check AI code for security risks.

AI CodeSoftware DevelopmentAI Code Security RisksVulnerability Management

Organizations that effectively track and manage open source dependencies are 85% more prepared to secure open source software compared to the overall average of 57%.

Open SourceSoftware SecurityOpen Source DependenciesVulnerability Management

63% of respondents that prioritize SBOM validation say they're highly prepared to evaluate third-party software.

Third-Party Software SecuritySoftware Supply ChainSBOM ValidationVulnerability Management

31.5% of organizations produce SBOMs due to industry regulations.

AISBOMs

96.1% of organizations are integrating open source AI models into their products.

AI

18% of companies are affected by "Shadow AI".

AIShadow AI

91% of audited applications contain outdated open source software components.

86% of audited applications contained open source vulnerabilities, with 81% containing high- or critical-risk vulnerabilities.

64% of open source components were transitive dependencies.

Automated verification of infrastructure security surged by more than 50%.

Black DuckBSIMM16·1y ago
Infrastructure SecurityAutomationApplication Security

Teams using attack intelligence to track emerging AI vulnerabilities increased by 10%.

Black DuckBSIMM16·1y ago
AI SecurityThreat IntelligenceApplication SecurityAI Vulnerabilities

Nearly 30% more organizations now produce SBOMs to meet transparency requirements.

Black DuckBSIMM16·1y ago
SBOMRegulatory Compliance

The number of organisations conducting adversarial tests (abuse cases) has doubled year-on-year.

Black DuckBSIMM15 Report·1y ago
Adversarial tests

The number of organisations employing research groups to develop new attack methods has grown by 30%.

Black DuckBSIMM15 Report·1y ago
Research groups

There has been a 67% increase in the number of organisations performing software composition analysis (SCA) on code repositories.

Black DuckBSIMM15 Report·1y ago
SCA

Developers reclaim an average of eight hours per week when using AI coding assistants.

ProductivityAI Coding Assistants

Nearly 90% of development teams encounter issues with AI-generated code.

Software DevelopmentAI ToolsAI Coding Assistants

86% of development professionals believe an AI agent or model should evaluate AI-generated code.

AI ToolsSecurityAI Coding Assistants

56% of development professionals prefer a dedicated AI security agent separate from the code-generation tool to evaluate AI-generated code.

AI SecuritySoftware DevelopmentAI Coding AssistantsAI Security Agent

30% of development professionals believe the same AI model that generated the code should also review it for security issues.

AI SecuritySoftware DevelopmentAI Coding Assistants

84% of developers prefer to keep a human in the loop via pull requests or real-time IDE suggestions when using AI-assisted development.

Human OversightSoftware DevelopmentAI Coding Assistants

AI coding assistants have 97% adoption among enterprise development teams.

Software DevelopmentAI ToolsAI Coding AssistantsEnterprise

97% of development teams have adopted AI coding assistants.

AI ToolsSoftware DevelopmentAI Coding Assistants

92% of development teams report improved productivity and release velocity when using AI coding assistants.

ProductivitySoftware DevelopmentAI Coding Assistants

30% of development teams have full governance in place for AI coding assistant adoption and oversight.

AI Coding GovernanceSoftware DevelopmentAI Coding Assistants

51% of development teams experience bottlenecks in security testing related to AI-generated code.

SecuritySoftware DevelopmentAI Coding AssistantsAI-Generated Code

53% of development teams have grown total code volume by over 25%.

Software DevelopmentCode VolumeAI Coding Assistants

52% of development teams experience bottlenecks in manual review related to AI-generated code.

Code ReviewSoftware DevelopmentAI Coding Assistants

68% of developers say it is extremely important to have a clear, automated system for tracking AI-generated code and measuring its impact for debugging, security, and accountability.

AI GovernanceSoftware DevelopmentSoftware Development

58% of development teams cite a major improvement in productivity and release velocity from AI coding assistants.

ProductivitySoftware DevelopmentAI Coding Assistants

Developers will spend 29% more time reviewing and validating AI-generated code, 29% more time on complex architecture and system design, and 23% more time on security verification and risk management.

Software DevelopmentAI Coding Assistants

76% of organizations check AI-generated code for security risks.

AI-Generated CodeAI RiskOpen Source Security

54% of organizations evaluate AI-generated code for IP and license risks.

LicensingAI RiskAI-Generated CodeOpen Source Security

56% of organizations assess quality issues in AI-generated code.

Software QualityAI RiskAI-Generated CodeOpen Source Security

The number of files per codebase grew by 74% year-over-year.

Codebase SizeSoftware CompositionOpen Source Security

68% of audited codebases contain license conflicts, a 12 percentage-point increase from 56% the previous year.

LicensingOpen SourceOpen Source Security

24% of organizations perform comprehensive IP, license, security, and quality evaluations for AI-generated code.

AI-Generated CodeAI RiskOpen Source Security

60% of organizations that perform automatic continuous monitoring report remediating critical software vulnerabilities within a day.

Vulnerability ManagementSoftware DevelopmentAutomatic Continuous MonitoringCritical Software Vulnerabilities

Only 24% of organizations have adopted comprehensive strategies to secure AI-generated code.

AI-Generated CodeSoftware DevelopmentAI-Generated Code SecurityVulnerability Management

35% of respondents cite interpreting and operationalizing complex regulatory requirements as their biggest challenge.

ComplianceRegulatory

Only 45% of the full respondent pool say they remediate critical software vulnerabilities within a day.

Vulnerability ManagementCritical Software VulnerabilitiesCritical Software Vulnerability Remediation

59% of respondents that prioritize SBOM validation typically respond to critical software vulnerabilities within one day.

SBOMSBOM ValidationVulnerability Management

95% of surveyed organizations reported using AI tools in software development.

AI ToolsSoftware Development

54% of organizations using at least four compliance controls remediate critical vulnerabilities within a day.

Compliance ControlsVulnerability ManagementCritical VulnerabilitiesCritical Vulnerability Remediation