November 7, 2025

Adventure Destinations League

Navigating Travel Wonders

Ten years of OSSRA: what a decade of data tells us about the state of open source security

Ten years of OSSRA: what a decade of data tells us about the state of open source security

When the first Open Source Security and Risk Analysis (OSSRA) report was published in 2015, the software landscape looked very different. Security teams were just beginning to grasp the implications of open source vulnerabilities, spurred by high-profile ones like the Heartbleed bug in OpenSSL which hit the front pages in 2014.

Developers, meanwhile, were continuing to use more and more open source to accelerate innovation, often without formal processes or visibility in place while their employers were just catching on and trying to get their arms around the issue.

link