Group Purchasing
Group Purchasing

Shift Left the Awareness and Detection of Developers Using Vulnerable Open-Source Software Components

Shift Left the Awareness and Detection of Developers Using Vulnerable Open-Source Software Components (PDF, 7.51MB)Published: 26 Mar, 2025
Created by:
Wellington Rampazo

The number of open-source software components, as well as the number of existing security vulnerabilities, has increased over the years. Although many vulnerabilities have been published in public data sources like the GitHub Advisories Database, the usage of vulnerable components is substantial, leading to security incidents with catastrophic consequences. Development teams tend to prioritize software releases with new features to achieve business goals over fixing issues or upgrading their software to more secure dependencies, mainly when the software has been released already.

The research presented in this paper demonstrates that companies can shift the detection and awareness of developers using vulnerable components left in the early development stages.

Implementing network monitoring added to a solution capable of identifying and querying for open-source software components with existing vulnerabilities allows developers to measure the risk and evolve into a secure solution in the earliest stage.