Report by Black Duck
“2026 Open Source Security and Risk Analysis” Report
9 FINDINGSPublished Feb 25, 2026
View Original Report →Key Findings
98% of codebases contain open source components.
Open SourceOpen Source Security
Mean vulnerabilities per codebase increased by 107% year-over-year.
VulnerabilitiesOpen Source Security
Open source component counts increased by 30% year-over-year.
Open SourceDependency ManagementOpen Source Security
76% of organizations check AI-generated code for security risks.
AI-Generated CodeAI RiskOpen Source Security
54% of organizations evaluate AI-generated code for IP and license risks.
LicensingAI RiskAI-Generated CodeOpen Source Security
56% of organizations assess quality issues in AI-generated code.
Software QualityAI RiskAI-Generated CodeOpen Source Security
The number of files per codebase grew by 74% year-over-year.
Codebase SizeSoftware CompositionOpen Source Security
68% of audited codebases contain license conflicts, a 12 percentage-point increase from 56% the previous year.
LicensingOpen SourceOpen Source Security
24% of organizations perform comprehensive IP, license, security, and quality evaluations for AI-generated code.
AI-Generated CodeAI RiskOpen Source Security