This white paper presents an analysis of open source risks associated with merger and acquisition (M&A) transactions, based on data from over 1,000 commercial codebases audited in 2023. It outlines the critical role of software composition analysis in due diligence, emphasizing the necessity for firms to audit target code to identify potential legal, security, and quality issues. The findings indicate that open source components were present in 99% of transactions, with an average of 1,635 components discovered per engagement. The paper details the prevalence of unpatched vulnerabilities, noting that 97% of transactions included at least one unpatched open source vulnerability, and 85% had components with license conflicts. It also discusses the implications of using outdated components and the challenges organizations face in tracking open source effectively. The report underscores the importance of automated open source management to mitigate risks and ensure compliance during M&A activities.