Open Source Security Management Neglected by Most Software Developers

December 9, 2013 Patricia Johnson

Free Webinar hosted by WhiteSource to Offer Tips and Strategies to Resolve the Issue

Open source has become a popular way to build software products, but security issues that accompany its widespread use are not sufficiently addressed. Rami Sass, CEO of WhiteSource, will host a free webinar, “Keeping a Closer Eye on Open Source: How and Why,” on December 18, 2013 at 9:30 a.m. (PST).

A recent WhiteSource study of 2,944 software projects with open source components found that 23% had security vulnerabilities. 85% used outdated open source libraries. A software security report by Veracode showed that 70% of applications fail to comply with basic enterprise security policies.

“As open source software becomes mainstream it requires the same level of security and reliability as proprietary software,” said Dan Yachin, Research Director at IDC’s Emerging Technologies group. “Organizations must therefore implement processes and solutions to promptly identify and fix vulnerabilities in their open source software. At the very least, they should be able to upgrade to a new version of an open source library when a vulnerability is discovered and fixed by the community,” he added.

Small and medium-size companies often lack the manpower and resources to build internal open source management systems. But the security risks of open source can’t be ignored.

“SMBs too often avoid the issue of open source management because of cost and effort, but the problem doesn’t go away and there’s an equal security risk factor for any size enterprise,” said Rami Sass, CEO of WhiteSource. “Sometimes SMBs use Excel spreadsheets because they’re low-cost, but it doesn’t take care of the security problem,” he added.

WhiteSource offers development teams a user-friendly SaaS platform for managing open source components. The WhiteSource platform is seamlessly weaved into the development management process, saving valuable time and effort.

The webinar agenda will include:

  • Open source security vulnerabilities and key statistics
  • Tracking and updating open source inventory down to the last dependency
  • How to be notified about security vulnerabilities and bug fixes
  • How to deploy an effective open source governance program

To pre-register for the webinar, please visit:

If you register and do not attend, we will send you a recording of the event.

About WhiteSource

WhiteSource is the leading provider of agile open source lifecycle management solutions. The White Source cloud-based service helps companies of all sizes fully realize the advantages of open source software while mitigating the legal, business and technical risks. WhiteSource is very affordable and easy to use — without over-burdening developers.

WhiteSource features a dynamic repository of information about open source libraries and their licenses, license risks, compliance requirements, security vulnerabilities, and new versions. The automated service makes it easy to implement best-practice business processes for open source adoption, usage, updates, and ongoing compliance. Founded in 2011, WhiteSource is a privately held company with offices in New York and Tel Aviv.

For more information, visit:

Previous Article
WhiteSource Announces Open Source Usage Practices Survey

The survey uncovers how CTOs and R&D Managers are managing the use of open source libraries by their develo...

Next Article
New WhiteSource Study Sheds Light on Open Source Security Risks
New WhiteSource Study Sheds Light on Open Source Security Risks

Most common cause of open source problems in commercial software projects is out-of-date open source librar...