JFrog
Software Supply Chain State of the Union 2024
Pages
34
Time to read
41 mins
Publication
Language
English
Pages
34
Time to read
41 mins
Publication
Language
English
This report serves as a comprehensive analysis of the current state of software supply chains in 2024, focusing on the complexities and risks associated with managing these ecosystems. It combines data from JFrog's extensive user base, CVE analysis, and a commissioned survey of 1,224 professionals in security, development, and operations. The report outlines the increasing diversity of programming languages used by organizations, with a significant number employing more than ten languages. It highlights the rapid growth of new packages in popular technologies such as Docker and npm, alongside the associated risks of vulnerabilities and malicious packages. The report also discusses the impact of AI on security practices, noting that while many organizations are adopting AI tools, there are concerns regarding security and compliance. Additionally, it emphasizes the need for organizations to adopt effective security frameworks and practices to mitigate risks in their software supply chains.