Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      CodeSOD: A Unique Way to Primary Key

      July 22, 2025

      BrowserStack launches Figma plugin for detecting accessibility issues in design phase

      July 22, 2025

      Parasoft brings agentic AI to service virtualization in latest release

      July 22, 2025

      Node.js vs. Python for Backend: 7 Reasons C-Level Leaders Choose Node.js Talent

      July 21, 2025

      The best CRM software with email marketing in 2025: Expert tested and reviewed

      July 22, 2025

      This multi-port car charger can power 4 gadgets at once – and it’s surprisingly cheap

      July 22, 2025

      I’m a wearables editor and here are the 7 Pixel Watch 4 rumors I’m most curious about

      July 22, 2025

      8 ways I quickly leveled up my Linux skills – and you can too

      July 22, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The Intersection of Agile and Accessibility – A Series on Designing for Everyone

      July 22, 2025
      Recent

      The Intersection of Agile and Accessibility – A Series on Designing for Everyone

      July 22, 2025

      Zero Trust & Cybersecurity Mesh: Your Org’s Survival Guide

      July 22, 2025

      Execute Ping Commands and Get Back Structured Data in PHP

      July 22, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      A Tomb Raider composer has been jailed — His legacy overshadowed by $75k+ in loan fraud

      July 22, 2025
      Recent

      A Tomb Raider composer has been jailed — His legacy overshadowed by $75k+ in loan fraud

      July 22, 2025

      “I don’t think I changed his mind” — NVIDIA CEO comments on H20 AI GPU sales resuming in China following a meeting with President Trump

      July 22, 2025

      Galaxy Z Fold 7 review: Six years later — Samsung finally cracks the foldable code

      July 22, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Tech & Work»Report: Keeping up with patches is the number one challenge when using open source software

    Report: Keeping up with patches is the number one challenge when using open source software

    April 8, 2025

    A new report is revealing that the most challenging aspect of utilizing open source projects is keeping up with updates and patches.  

    According to the 2025 State of Open Source report from Perforce Software, the Eclipse Foundation, and the Open Source Initiative, when asked to rank challenges on a scale of one to five, over half of the 433 respondents ranked the following as a three or higher:

    • Keeping software updated
    • Meeting security and compliance requirements
    • Maintaining end-of-life (EOL) versions

    “These three are, of course, very connected — keeping up with updates and patches and maintaining end-of-life versions are key to meeting security and compliance requirements. Every year the responses to this question remind us that it is an uphill battle for organizations to stay on the latest versions and/or have access to security updates and patches for EOL software in their stacks,” the report authors wrote. 

    For example, CentOS 7 reached EOL in June 2024 and at the time the survey was conducted (between September and December 2024), 40% of the largest enterprises were still using it and it was the third most common Linux distribution. 

    Further, 28% don’t have a plan in place for addressing CentOS vulnerabilities and 8% said they don’t plan to patch CentOS CVEs. Only 19% percent say they have an LTS vendor providing patches and 13% have an in-house team that does it. 

    RELATED: Sonatype reveals 18,000 malicious open source packages in its Q1 Open Source Malware Index

    When respondents who are using the proprietary version of open source software were asked what’s preventing them from using the open source version, 44% said it was the professional support and maintenance that comes with it. This was the most popular answer by a wide margin, with the next most popular reason—additional features and customization—coming in at 25%. 

    Where open source is being used

    According to the report, the top category for open source usage was cloud and container technologies, with 40% of respondents using open source software in that area. The most popular cloud native open source projects were Docker (59% of respondents using it) and Kubernetes (39%). 

    Databases and data technologies were the second most heavily used open source software, at 33% of respondents. The most popular ones were PostgreSQL (51%), MySQL (37%), and MariaDB (31%).

    The report found that almost half of organizations do not have a lot of confidence in their data management operations. When asked to rank their confidence in Big Data management from one to five, 47% of respondents scored themselves as two or less and less than 10% ranked themselves as a 5. 

    They found that the biggest challenge in working with open source databases or other data technologies was lack of personnel or personnel experience, with over three quarters of respondents saying so.

    “For this reason, some turn to commercial, managed solutions (i.e. Cloudera), but the trade-off is cost. If the organization cannot afford the commercially managed platform, they are stuck with the operational and personnel costs of these complex stacks, often needing to fall back on less-experienced DevOps engineers or turn to outside consultants when they cannot solve problems,” the report states. 

    The third most popular category for open source usage this year was programming languages and frameworks (33%), which was an increase from the previous year. The report authors believe this is an indication that more organizations are now developing open source software and not just consuming it. 

    The report indicates that open source programming languages are the number one investment area for small companies with 1-20 employees, which suggests they are creating their own solutions in-house. 

    The smallest organizations are also contributing to open source projects way more than larger organizations with 5,000 employees or more. Fifty seven percent of small companies contributed compared to 25% of large companies. 

    “The State of Open Source Report demonstrates that big enterprises are not necessarily more mature when it comes to their open source strategy,” said Stefano Maffulli, executive director of the Open Source Initiative (OSI). “It is encouraging to see that even very small organizations are committed to not just consuming open source, but giving back to the community by contributing code and supporting OSS foundations.”

    The post Report: Keeping up with patches is the number one challenge when using open source software appeared first on SD Times.

    Source: Read More 

    news
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleGitHub introduces security campaigns to help developers reduce security debt
    Next Article How Meta’s new teen accounts aim to keep your kids safer on Facebook

    Related Posts

    Tech & Work

    CodeSOD: A Unique Way to Primary Key

    July 22, 2025
    Tech & Work

    BrowserStack launches Figma plugin for detecting accessibility issues in design phase

    July 22, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    nativephp/electron

    Development

    Track Metrics Effortlessly with Laravel’s Context Increment and Decrement Methods

    Development

    CVE-2025-1753 – LLama-Index OS Command Injection Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2023-37535 – HCL Domino Volt and Domino Leap Unvalidated Request Parameter Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    News & Updates

    The Gears of War Reloaded beta is upon us, here’s how you can take part

    June 13, 2025

    The Gears of War Reloaded beta is here and there are a few different ways…

    Researchers teach LLMs to solve complex planning challenges

    April 2, 2025

    Error’d: Nicknamed Nil

    July 18, 2025

    Steering into New Embedding Spaces: Analyzing Cross-Lingual Alignment Induced by Model Interventions in Multilingual Language Models

    July 22, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.