2026 Open Source Security and Risk Analysis Report – Software Governance in the AI Era – Black Duck Software, Inc.
https://www.blackduck.com/content/dam/black-duck/en-us/reports/rep-ossra.pdf
The “Open Source Security and Risk Analysis” (OSSRA) report has been the industry’s definitive look at the state of open source code for a decade. Each year, we analyze anonymized findings from commercial codebases audited by the Black Duck Audit Services team, and this provides an unmatched, real-world view of how open source is used—and sometimes misused—across every major industry. [...]





