Black Duck has announced the release of a new report, Navigating Software Supply Chain Risk in a Rapid-Release World.
The study, conducted by UserEvidence, is based on a survey of 540 software security leaders and practitioners. The report highlights a critical disconnect: while 95% of organizations are leveraging AI tools for software development, just 24% are implementing comprehensive intellectual property, licence, security, and quality evaluations for AI-generated code. This oversight exposes the software supply chain to potentially severe and unaddressed risks.
Key findings include:
AI adoption outpaces security: most organizations are embracing AI in development, yet robust security protocols for AI-generated code are largely absent, potentially creating new attack vectors. Although 76% of respondents check AI-generated code for security risks, only 24% perform intellectual property, licence, security, and quality evaluations for such code.
Dependency management is key to preparedness: organizations that are highly effective at tracking and managing open source dependencies are significantly more prepared (85%) to secure open source software, compared to the overall average (57%).
Automation drives faster remediation: of the respondents that perform automatic continuous monitoring, 60% report remediating critical software vulnerabilities within a day. In contrast, only 45% of the full respondent pool say they remediate critical software vulnerabilities within a day, showing that organizations that have not implemented automatic continuous monitoring are at a clear disadvantage in protecting the software supply chain.
SBOM validation enhances third-party security: validating software bills of materials (SBOMs) from external suppliers significantly improves an organization’s ability to evaluate third-party software and respond to critical vulnerabilities. Of the respondents that prioritise SBOM validation, 63% of those that always validate SBOMs say they are highly prepared to evaluate third-party software, and 59% typically respond to critical software vulnerabilities within one day.
Compliance controls boost efficiency: organizations with more compliance controls in place demonstrate greater efficiency in remediating critical software vulnerabilities. Of the respondents that use at least three compliance controls, 49% remediate critical vulnerabilities within a day. This percentage rises to 54% for respondents that use at least four compliance controls. Additionally, 35% of respondents cite interpreting and operationalising complex regulatory requirements as their biggest challenge.






