Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»New report finds signs of slowing supply chain security momentum, plateaued DevOps maturity

    New report finds signs of slowing supply chain security momentum, plateaued DevOps maturity

    December 7, 2024

    The number of security challenges companies are facing continue to grow, but organizations are beginning to display signs of “AppSec exhaustion,” or decreased engagement in security practices. 

    This is according to Snyk’s new State of Open Source report, which found that dependency tracking and code ship frequency has remained largely unchanged since last year. There was only a slight increase in the percentage of teams tracking all dependencies and a slight decrease in the number of teams only tracking direct dependencies. 

    The majority of companies who don’t track dependencies at all do run software composition analysis, which Snyk believes indicates that their tracking isn’t systematic but they do check dependencies and open source components for vulnerabilities. 

    There was also a stagnation in code ship frequency, which Snyk says is an indication that DevOps maturity has reached a plateau, as improved tooling and developer experience should facilitate faster code iteration. 

    Other signs of AppSec exhaustion are that none of the eight AppSec methods Snyk included in their survey were used by more than 70% of respondents. Software composition analysis is most popular, but is only used by 69% of respondents. 

    Additionally, there was a decline in the percentage of organizations implementing new tooling to address supply chain vulnerabilities, dropping from 60% in 2023 to 49% in 2024. There was also a decrease in the number of organizations investing in training on supply chain security, from 53% in 2023 to 35% in 2024. 

    “These reductions suggest that organizations may be feeling overwhelmed or fatigued by the continuous pressure of supply chain security demands, leading to reduced commitment to preventive actions. This may indicate fatigue, relatively stable percentage of organizations unaffected by supply chain vulnerabilities further supports this potential fatigue, as some may opt to disengage rather than continually invest in complex and evolving security requirements,” Snyk wrote in the report. 

    Other interesting findings are that:

    • 52% of organizations failed to meet vulnerability mitigation SLAs
    • 45% has to replace vulnerable build components
    • Fewer than 25% of organizations regularly audit their software supply chain

    For the report, Snyk surveyed 453 development and security professionals from industries such as automotive, business services, communications, education, energy & utilities, entertainment/media, financial services, government, and SaaS technology.

    The post New report finds signs of slowing supply chain security momentum, plateaued DevOps maturity appeared first on SD Times.

    Source: Read More 

    news
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleNew ScyllaDB Release Delivers Unprecedented Elasticity & Efficiency via “Tablets” Architecture
    Next Article Amazon announces its own series of foundation models, Amazon Nova

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 17, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-4610 – WordPress WP-Members Membership Plugin Stored Cross-Site Scripting Vulnerability

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Mako – Extremely fast, production-grade web bundler based on Rust.

    Development

    accessiBe Launches accessFlow, Comprehensive Tool for Driving Native Accessibility in Web Development Projects

    Tech & Work

    No, Brad Pitt isn’t in love with you

    Development

    Free DOOM: The Dark Ages Premium Edition? NVIDIA is making it happen.

    News & Updates

    Highlights

    Star Wars: Bounty Hunter is finally coming to Xbox and PC, 22 years after its original release

    June 28, 2024

    On August 1st, Star Wars: Bounty Hunter, a 2002 game people treasure, will return on…

    How to Bring Zero Trust to Wi-Fi Security with a Cloud-based Captive Portal?

    January 17, 2025

    Representative Line: Time for Identification

    March 26, 2025

    Kraken vs Certik: A Dispute Over a $3 Million Zero-Day and Bug Bounty Ethics

    June 20, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.