Get the latest tech news
Linux Foundation report highlights the true state of open-source libraries in production apps
A new report from the Linux Foundation highlights the true state of open source libraries in production apps.
There are many metrics to track the prevalence of open-source components, such as GitHub stars and downloads, but they don’t paint the full picture of how they’re being used in production codebases. The extensive report highlights the shift toward memory-safe programming, with Rust adoption surging. And from a security concern perspective, it points to the continued reliance on Python 2, as well as a lack of standardized naming for components — this can increase the risk of dependency confusion and malicious package injection.
Or read this on TechCrunch