Report by Black Duck

“2025 Open Source Security and Risk Analysis” Report

9 FINDINGSPublished Feb 25, 2025
View Original Report →

Key Findings

91% of audited applications contain outdated open source software components.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

86% of audited applications contained open source vulnerabilities, with 81% containing high- or critical-risk vulnerabilities.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

The number of open source files in an average application has tripled over the last four years.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

64% of open source components were transitive dependencies.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

56% of all audited applications had license conflicts.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

97% of all applications evaluated contained open source software.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

Nearly 30% of component license conflicts were caused by transitive dependencies.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

90% of the applications contain components more than 10 versions behind the most current version.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025

33% had open source software components with no license or a customized license.

Black Duck“2025 Open Source Security and Risk Analysis” Report·Feb 25, 2025