Report by DataDog

State of DevSecOps

8 FINDINGSPublished Feb 26, 2026
View Original Report →

Key Findings

Services using supported language versions face exploitable vulnerabilities in 31% of cases

DataDogState of DevSecOps·5mo ago
DevSecOpsVulnerabilitiesExploitable Vulnerabilities

Services using end-of-life language versions face exploitable vulnerabilities in 50% of cases

DataDogState of DevSecOps·5mo ago
DevSecOpsExploitable VulnerabilitiesLegacy SoftwareVulnerabilities

50% of organizations adopt new library versions within 24 hours of release

DataDogState of DevSecOps·5mo ago
DevSecOpsSoftware Supply ChainDependency Management

42% of services rely on libraries that are no longer actively maintained

DataDogState of DevSecOps·5mo ago
DevSecOpsDependency Management

87% of organizations have at least one known exploitable vulnerability in deployed services

DataDogState of DevSecOps·5mo ago
DevSecOpsExploitable VulnerabilitiesVulnerabilities

Only 4% of organizations pin all public GitHub Actions to a specific version using commit hashes

DataDogState of DevSecOps·5mo ago
DevSecOps

The median software dependency is 278 days out of date, 63 days further behind than last year

DataDogState of DevSecOps·5mo ago
DevSecOpsSoftware DependenciesSoftware Maintenance

18% of vulnerabilities labeled "critical" remain critical once runtime context is applied

DataDogState of DevSecOps·5mo ago
DevSecOpsVulnerability PrioritizationRuntime Security