Open Source, Open Threats? Investigating Security Challenges in Open-Source Software
Seyed Ali Akhavani, Behzad Ousat, Amin Kharraz

TL;DR
This study analyzes a large dataset of OSS vulnerabilities, revealing a rapid increase in reported issues, longer vulnerability lifespans, and ecosystem-specific security challenges, especially malicious packages, highlighting critical security concerns in open-source development.
Contribution
It provides a comprehensive analysis of OSS vulnerability trends, identifying key CWEs, ecosystem-specific patterns, and the prevalence of malicious packages, offering insights for improving security practices.
Findings
Reported vulnerabilities increased by 98% annually.
Vulnerability lifespan grew by 85%, indicating declining security.
Malicious packages constitute 49% of NPM reports.
Abstract
Open-source software (OSS) has become increasingly more popular across different domains. However, this rapid development and widespread adoption come with a security cost. The growing complexity and openness of OSS ecosystems have led to increased exposure to vulnerabilities and attack surfaces. This paper investigates the trends and patterns of reported vulnerabilities within OSS platforms, focusing on the implications of these findings for security practices. To understand the dynamics of OSS vulnerabilities, we analyze a comprehensive dataset comprising 31,267 unique vulnerability reports from GitHub's advisory database and Snyk.io, belonging to 14,675 packages across 10 programming languages. Our analysis reveals a significant surge in reported vulnerabilities, increasing at an annual rate of 98%, far outpacing the 25% average annual growth in the number of open-source software…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsOpen Source Software Innovations · Digital and Cyber Forensics · Information and Cyber Security
