Report by Black Duck

“2026 Open Source Security and Risk Analysis” Report

9 FINDINGSPublished Feb 25, 2026
View Original Report →

Key Findings

98% of codebases contain open source components.

Open SourceOpen Source Security

Mean vulnerabilities per codebase increased by 107% year-over-year.

VulnerabilitiesOpen Source Security

Open source component counts increased by 30% year-over-year.

Open SourceDependency ManagementOpen Source Security

76% of organizations check AI-generated code for security risks.

AI-Generated CodeAI RiskOpen Source Security

54% of organizations evaluate AI-generated code for IP and license risks.

LicensingAI RiskAI-Generated CodeOpen Source Security

56% of organizations assess quality issues in AI-generated code.

Software QualityAI RiskAI-Generated CodeOpen Source Security

The number of files per codebase grew by 74% year-over-year.

Codebase SizeSoftware CompositionOpen Source Security

68% of audited codebases contain license conflicts, a 12 percentage-point increase from 56% the previous year.

LicensingOpen SourceOpen Source Security

24% of organizations perform comprehensive IP, license, security, and quality evaluations for AI-generated code.

AI-Generated CodeAI RiskOpen Source Security