Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
- Destacamos »
- software Anti Blanqueo
SILVER SPRING, MD -- (Marketwire) -- 04/23/12 -- Sonatype, the company transforming software development, today announced the findings of its annual Open Source Software Development Survey that looks to identify how organizations adopt, use and support open-source software (OSS) according to more than 2,500 developers, architects and IT managers across all industries, company sizes and geographic regions. The survey findings show that organizations of all sizes continue to adopt open-source at an accelerated pace, but lack of internal controls and flawed processes continue to be a challenge -- putting organizations at unnecessary risk.
Open-source is a strategic asset and has earned equal footing with proprietary software in the enterprise. Nearly 80 percent of those surveyed use open-source tools, half standardize on an open-source development infrastructure stack, and two-thirds contribute to open-source projects. Key to modern development practices is the use of open-source components to build mission-critical applications. While reliance on open-source components increases year-over-year, limitations on the visibility, control and management of their use throughout the enterprise continues to plague organizations.
"As open-source and better collaborative tools have increased reuse of software libraries and components it can be difficult to know what exactly is in your product," said Stephen O'Grady, Principal Analyst with RedMonk. "Sonatype's recent survey highlights the potential dangers of ignorance, and the need for better component intelligence."
Key Finding #1: Reliance on Open-Source Components Increases
The Central Repository ("Central") continues to be the software development industry's most widely used resource for the exchange of open-source components.
Key Finding #2: Management of Component Usage Increases
Open-source components are widely used as the building blocks for modern-day applications, but organizations currently have limited control over how they are selected or utilized. When compared to the 2011 survey results, which had a smaller survey pool of 1,600, we see corporate policies and governance practices on the rise, with regulated industries more likely to have policies strictly enforced.
Key Finding #3: Shortcomings in Policy Enforcement
While the percentage of organizations implementing open-source policies grew this year, a disconnect remains between development processes, component usage and policy enforcement. The lack of policy enforcement may be due, in part, to confusion over who owns or is responsible for monitoring and managing open-source usage.
The survey findings suggest an overwhelming desire by developers for a notification infrastructure -- a simple, non-intrusive way to determine if a component that is in use has changed in an important way, such as new version release or the discovery of a security flaw or defect.
"The survey results confirm what we see and hear from our customers on a daily basis -- open-source has become the backbone of custom application development. Yet it brings with it a complex component ecosystem with no notification infrastructure in place. This leaves organizations exposed to security, quality and IP risks," said Charles Gold, CMO of Sonatype. "The compounding reality is that when issues do arise, the effects are viral while the fixes are not. Sonatype is focused on addressing these critical challenges by delivering a means for bridging critical awareness gaps and a platform for delivering knowledge directly into the tools that developers and development managers use every day."
For a complete view of the survey results and detailed information about the survey pool, organizations represented and methodology used, visit http://www.sonatype.com/people/wp-content/uploads/2012/03/2012-sonatype-survey-findings-PDF.pdf
About Sonatype Inc.
Sonatype is transforming software development by ensuring the integrity of the modern software supply chain. Sonatype's tools and information services improve visibility and control over component-based software development, enabling better collaboration between development teams for improved overall quality, while reducing the risks associated with security and licensing. Sonatype operates the Central Repository, the industry's primary source for open-source components, and is a leader in such open-source projects as Nexus, Apache Maven, m2eclipse and Hudson. The company was founded by Jason van Zyl, the creator of Apache Maven and is privately held with investments from Accel Partners, Bay Partners, Hummer Winblad Venture Partners and Morgenthaler Ventures. Visit: www.sonatype.com or follow Sonatype on Twitter @SonatypeCM.
Apache, Apache Maven and Maven are trademarks of the Apache Software Foundation.
Add to Digg Bookmark with del.icio.us Add to Newsvine
Media Contacts:
April Harned
PR for Sonatype
Email Contact
646-246-0484
Publicamos interesante Informe de más de 48 págs y varios videos demostrativos sobre los posibles ataques a los robots de montaje de las fábricas. ... Leer más ►
Publicado el 22-Jun-2017 • 10.48hs
Publicado el 20-Jun-2017 • 20.22hs
Dirigido tanto a los principiantes, como a los expertos en seguridad informática y sistemas de control industrial (ICS), este libro ayudará a los lectores a comprender mejor la protección de normas de control interno de las amenazas electrónicas. ... Leer más ►
Publicado el 3-Ene-2012 • 20.16hs
Publicado el 25-Set-2009 • 01.26hs
Publicado el 17-Dic-2008 • 08.32hs
Publicado el 11-Oct-2016 • 12.48hs
Publicado el 15-Mar-2016 • 11.59hs
Publicado el 2-Feb-2017 • 11.38hs
Publicado el 20-Jun-2014 • 17.17hs
Publicado el 31-May-2011 • 05.13hs
Publicado el 25-Set-2008 • 17.54hs
Publicado el 1-Set-2016 • 16.11hs
Publicado el 31-Ago-2016 • 18.53hs
Publicado el 19-Ene-2017 • 15.47hs
Publicado el 4-Jul-2016 • 18.51hs