aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • DevOps
  • Programming
  • Software
  • Software Engineering

2020 State of the Software Supply Chain Report Released; Sonatype Reveals New Speed And Security Benchmarks

  • aster.cloud
  • August 13, 2020
  • 3 minute read

Sonatype, the company that scales DevOps through open source governance and software supply chain automation, released its sixth annual State of the Software Supply Chain Report.

For the second year in a row, Sonatype partnered with researchers Gene Kim from IT Revolution and Dr. Stephen Magill, CEO at MuseDev to examine how high performing teams successfully demonstrate superior risk management outcomes while maintaining high levels of productivity.


Partner with aster.cloud
for your next big idea.
Let us know here.



From our partners:

CITI.IO :: Business. Institutions. Society. Global Political Economy.
CYBERPOGO.COM :: For the Arts, Sciences, and Technology.
DADAHACKS.COM :: Parenting For The Rest Of Us.
ZEDISTA.COM :: Entertainment. Sports. Culture. Escape.
TAKUMAKU.COM :: For The Hearth And Home.
ASTER.CLOUD :: From The Cloud And Beyond.
LIWAIWAI.COM :: Intelligence, Inside and Outside.
GLOBALCLOUDPLATFORMS.COM :: For The World's Computing Needs.
FIREGULAMAN.COM :: For The Fire In The Belly Of The Coder.
ASTERCASTER.COM :: Supra Astra. Beyond The Stars.
BARTDAY.COM :: Prosperity For Everyone.

 

The report analyzes over 1.5 trillion open source download requests, 24,000 open source projects, and 5,600 enterprise development teams.  Furthermore, in-depth survey research across a wide variety of organizations identified four types of software engineering teams with markedly different levels of performance as it relates to software supply management practices and open source governance.

  • High Performance Teams: high productivity, great risk management outcomes
  • Security First Teams: low productivity, great risk management outcomes
  • Productivity First Teams: high productivity, poor risk management outcomes
  • Low Performers Teams: low productivity, poor risk management outcomes

When compared to their Low Performer peers, High Performers demonstrated:

  • 15x higher deployment frequency
  • 26x faster detection and remediation of vulnerable OSS components
  • 5.7x less time required for developers to be productivity when switching teams
  • 1.5x more likely for employees to recommend their organizations as a great place to work

When compared to Security First teams, High Performers were:

  • 59% more likely to be using software composition analysis (SCA) tools
  • 28% more likely to enforce governance policies in Continuous Integration (CI)
  • 56% more likely to have centrally-managed CI infrastructure
  • 51% more likely to maintain a centralized record of SBOMs for applications

“Many have argued that effective risk management practices are always at the expense of developer productivity, but this year’s report provides strong evidence to the contrary. Faster innovation and better risk management are not mutually exclusive,” said Wayne Jackson, CEO of Sonatype. “High Performance engineering teams are accelerating velocity while simultaneously reducing security risks. Adding to these successful business outcomes, developers in High Performance teams demonstrate higher levels of job satisfaction.”

The report also evaluated 24,000 open source projects to determine practices of the top-performing suppliers feeding components into software supply chains. Researchers found exemplary OSS projects demonstrated:

  • 530x faster mean time to update (MTTU) dependencies
  • 1.5x more frequent releases
  • 2.5x greater popularity
  • 173x less likely to have at least one dependency out of date
Read More  7 Sudo Myths Debunked

“We found that high performers are able to simultaneously achieve security and productivity objectives,” said Gene Kim, DevOps researcher and author of the WSJ bestselling book, The Unicorn Project.  “It’s fantastic to gain a better understanding of the principles and practices of how this is achieved, as well as their measurable outcomes.”

“It was really exciting to find so much evidence that this much-discussed tradeoff between security and productivity is really a false dichotomy. With the right culture, workflow, and tools development teams can achieve great security and compliance outcomes together with class-leading productivity,” said Dr. Stephen Magill, Principal Scientist at Galois & CEO of MuseDev.

The study also reveals new milestones in open source software development, adversarial activity, and government influence, including:

  • 430% increase in next generation software supply chain attacks over the past year (page 6)
  • 373,000 average downloads of open source component per company, of which 8.3% were known vulnerable (page 33)
  • U.S., U.K., and Australian government initiatives designed to protect software supply chains and strengthen the foundations of open source (see page 35 )

About the State of the Software Supply Chain Report

The 2020 State of the Software Supply Chain Report blends a broad set of public and proprietary data with expert research and analysis to identify exemplary software development practices. Now in its sixth year, it is the longest-running research on open source software development and application security practices of its kind.

Additional Resources

  • Read the 2020 State of the Software Supply Chain report
  • Read our blog
  • Create a Software Bill of Materials for free
  • Learn more about Sonatype’s software supply chain automation solutions
Read More  Sonatype And NeuVector Partner To Centralize Container And Open Source Security

About Sonatype

Sonatype is the leader in software supply chain automation technology with more than 350 employees, over 1,000 enterprise customers, and is trusted by more than 10 million software developers. Sonatype’s Nexus platform enables DevOps teams and developers to automatically integrate security at every stage of the modern development pipeline by combining in-depth component intelligence with real-time remediation guidance. For more information, please visit Sonatype.com, or connect with Facebook, Twitter, or LinkedIn.


For enquiries, product placements, sponsorships, and collaborations, connect with us at [email protected]. We'd love to hear from you!

Our humans need coffee too! Your support is highly appreciated, thank you!

aster.cloud

Related Topics
  • MuseDev
  • Sonatype
  • State of the Software Supply Chain Report
You May Also Like
View Post
  • Software
  • Technology

Canonical Releases Ubuntu 25.04 Plucky Puffin

  • April 17, 2025
View Post
  • Software
  • Technology

IBM Accelerates Momentum in the as a Service Space with Growing Portfolio of Tools Simplifying Infrastructure Management

  • March 27, 2025
View Post
  • Software Engineering
  • Technology

Claude 3.7 Sonnet and Claude Code

  • February 25, 2025
View Post
  • Engineering
  • Software Engineering

This Month in Julia World

  • January 17, 2025
View Post
  • Engineering
  • Software Engineering

Google Summer of Code 2025 is here!

  • January 17, 2025
Vehicle manufacturing
View Post
  • Software

IBM Study: Vehicles Believed to be Software Defined and AI Powered by 2035

  • December 12, 2024
aster-cloud-tux-gaming
View Post
  • Computing
  • Gears
  • Software

5 best Linux distributions for gamers in 2024

  • September 11, 2024
Crab
View Post
  • Gears
  • Learning
  • Software

The Best Friends for a Rustacean. Top Books in Learning Rust.

  • August 25, 2024

Stay Connected!
LATEST
  • cookies-food-photographer-jennifer-pallian-OfdDiqx8Cz8-unsplash 1
    What is a cookie?
    • June 6, 2025
  • 8 benefits of AI as a service
    • June 6, 2025
  • 3
    Where is the cloud headed?
    • June 6, 2025
  • 4
    Cloud breaches are surging, but enterprises aren’t quick enough to react
    • June 6, 2025
  • 5
    Enterprises are keen on cloud repatriation – but not for all workloads
    • June 4, 2025
  • 6
    The Summer Adventures : Hiking and Nature Walks Essentials
    • June 2, 2025
  • 7
    Just make it scale: An Aurora DSQL story
    • May 29, 2025
  • 8
    Reliance on US tech providers is making IT leaders skittish
    • May 28, 2025
  • Examine the 4 types of edge computing, with examples
    • May 28, 2025
  • AI and private cloud: 2 lessons from Dell Tech World 2025
    • May 28, 2025
about
Hello World!

We are aster.cloud. We’re created by programmers for programmers.

Our site aims to provide guides, programming tips, reviews, and interesting materials for tech people and those who want to learn in general.

We would like to hear from you.

If you have any feedback, enquiries, or sponsorship request, kindly reach out to us at:

[email protected]
Most Popular
  • Understand how Windows Server 2025 PAYG licensing works
    • May 20, 2025
  • By the numbers: How upskilling fills the IT skills gap
    • May 21, 2025
  • Weigh these 6 enterprise advantages of storage as a service
    • May 28, 2025
  • 4
    Broadcom’s ‘harsh’ VMware contracts are costing customers up to 1,500% more
    • May 28, 2025
  • 5
    TD Synnex named as UK distributor for Cohesity
    • May 28, 2025
  • /
  • Technology
  • Tools
  • About
  • Contact Us

Input your search keywords and press Enter.