Key Findings
Services using supported language versions face exploitable vulnerabilities in 31% of cases
DevSecOpsVulnerabilitiesExploitable Vulnerabilities
Services using end-of-life language versions face exploitable vulnerabilities in 50% of cases
DevSecOpsExploitable VulnerabilitiesLegacy SoftwareVulnerabilities
50% of organizations adopt new library versions within 24 hours of release
DevSecOpsSoftware Supply ChainDependency Management
42% of services rely on libraries that are no longer actively maintained
DevSecOpsDependency Management
87% of organizations have at least one known exploitable vulnerability in deployed services
DevSecOpsExploitable VulnerabilitiesVulnerabilities
Only 4% of organizations pin all public GitHub Actions to a specific version using commit hashes
DevSecOps
The median software dependency is 278 days out of date, 63 days further behind than last year
DevSecOpsSoftware DependenciesSoftware Maintenance
18% of vulnerabilities labeled "critical" remain critical once runtime context is applied
DevSecOpsVulnerability PrioritizationRuntime Security