Get the latest tech news

Linux Foundation report highlights the true state of open-source libraries in production apps


A new report from the Linux Foundation highlights the true state of open source libraries in production apps.

There are many metrics to track the prevalence of open-source components, such as GitHub stars and downloads, but they don’t paint the full picture of how they’re being used in production codebases. The extensive report highlights the shift toward memory-safe programming, with Rust adoption surging. And from a security concern perspective, it points to the continued reliance on Python 2, as well as a lack of standardized naming for components — this can increase the risk of dependency confusion and malicious package injection.

Get the Android app

Or read this on TechCrunch

Read more on:

Photo of Linux Foundation

Linux Foundation

Photo of source libraries

source libraries

Photo of production apps

production apps

Related news:

News photo

Jim Zemlin, 'head janitor of open source,' marks 20 years at Linux Foundation

News photo

Jim Zemlin, 'Head Janitor of Open Source,' Marks 20 Years At Linux Foundation

News photo

AWS brings OpenSearch under the Linux Foundation umbrella