CARVIEW |
Select Language
HTTP/2 200
date: Sat, 11 Oct 2025 04:58:42 GMT
content-type: text/html;charset=utf-8
content-encoding: gzip
x-vhost: blackduck
content-security-policy: default-src 'self' 'unsafe-hashes' 'unsafe-inline' 'unsafe-eval' data: blob: edge.adobedc.net adobedc.demdex.net *.adobe.com *.adobe.io cdn.cookielaw.org assets.adobedtm.com kit.fontawesome.com ka-p.fontawesome.com munchkin.marketo.net adobedc.demdex.net snap.licdn.com *.drift.com js.driftt.com js.zi-scripts.com j.6sc.co geolocation.onetrust.com ipv6.6sc.co c.6sc.co b.6sc.co epsilon.6sense.com px.ads.linkedin.com static.cloud.coveo.com boards.greenhouse.io *.mktoresp.com ws.zoominfo.com job-boards.greenhouse.io api.company-target.com *.org.coveo.com synopsysnonproduction2yln023as.analytics.org.coveo.com *.brighttalk.com brighttalk.com js.zi-scripts.com *.blackduck.com blackduck.com players.brightcove.net *.brightcove.com manifest.prod.boltdns.net *.brightcovecdn.com googletagmanager.com *.googletagmanager.com *.google.com *.google.ca *.google.co.uk google.co.in google.com *.google-analytics.com google-analytics.com googleads.g.doubleclick.net td.doubleclick.net *.googleapis.com *.gstatic.com *.leadspace.com *.clarity.ms *.bing.com *.bing.net *.bing-int.com *.6sc.co *.6sense.co 846-esg-342.mktoutil.com *.youtube.com;
cache-control: max-age=300
expires: Sat, 11 Oct 2025 05:00:20 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
strict-transport-security: max-age=31536000
x-served-by: cache-bom-vanm7210055-BOM
x-cache: MISS
x-timer: S1760158520.525851,VS0,VS0,VE1306
vary: Accept-Encoding,User-Agent
last-modified: Sat, 11 Oct 2025 04:55:20 GMT
cf-cache-status: HIT
server: cloudflare
cf-ray: 98cbc8ad29ffb080-BLR
Open Source Security & Risk Analysis Report (OSSRA) | Black Duck
“2025 Open Source Security and Risk Analysis” Report
Insights into open source security trends and recommendations for securing your software supply chain
Download the latest OSSRA
What's inside the report
The annual “Open Source Security and Risk Analysis” (OSSRA) report, now in its tenth edition, examines vulnerabilities and license conflicts found in over 950 codebases across 16 industries. The report offers recommendations to help security, legal, risk, and development teams better understand open source security and the license risk landscape, especially in the context of securing the software supply chain. The OSSRA highlights the need for organizations to have complete visibility into their code, proactively manage open source risk, and adopt strong security and compliance practices.
Download the “2025 Open Source Security and Risk Analysis” report to learn
- What types of vulnerabilities are prevalent in open source software
- The current challenges in licensing and compliance
- Key recommendations for securing your software supply chain
- The importance of implementing software composition analysis tools to generate accurate Software Bills of Materials
