{"id":110893,"date":"2023-10-17T09:10:18","date_gmt":"2023-10-17T07:10:19","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/oczenka-problem-s-soprovozhdeniem-otkrytyh-proektov-i-ispolzovaniem-staryh-zavisimostej"},"modified":"2023-10-17T09:10:18","modified_gmt":"2023-10-17T07:10:19","slug":"oczenka-problem-s-soprovozhdeniem-otkrytyh-proektov-i-ispolzovaniem-staryh-zavisimostej","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/oczenka-problem-s-soprovozhdeniem-otkrytyh-proektov-i-ispolzovaniem-staryh-zavisimostej","title":{"rendered":"Evaluarea problemelor de \u00eentre\u021binere a proiectelor open source \u0219i utilizarea dependen\u021belor vechi","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Compania Sonatype, specializat\u0103 \u00een protec\u021bia \u00eempotriva atacurilor ce manipul\u0103m componente software \u0219i dependen\u021be (supply chain), a publicat rezultatele unei cercet\u0103ri (PDF, 62 pagini) privind problemele cu dependen\u021bele \u0219i \u00eentre\u021binerea proiectelor open-source \u00een limbajele Java, JavaScript, Python \u0219i .NET, disponibile \u00een repositoarele Maven Central, NPM, PyPl \u0219i Nuget. Pe parcursul unui an, s-a observat o cre\u0219tere a num\u0103rului de proiecte \u00een ecosistemele open-source urm\u0103rite cu o medie de 29%. Num\u0103rul desc\u0103rc\u0103rilor pachetelor din repositoarele analizate \u00een 2023 a crescut cu 33%, dar, pentru compara\u021bie, \u00een 2021, num\u0103rul desc\u0103rc\u0103rilor a crescut cu 73%.    <\/p>\n<p>Activitatea d\u0103un\u0103toare \u00een depozitele de software a crescut semnificativ \u2014 de la \u00eenceputul anului au fost identificate 245 de mii de pachete d\u0103un\u0103toare, iar num\u0103rul atacurilor \u00eenregistrate, \u021bintind substituirea dependen\u021belor, s-a dublat.     <center><img decoding=\"async\" alt=\"Evaluarea problemelor de \u00eentre\u021binere a proiectelor open source \u0219i utilizarea dependen\u021belor vechi\" src=\"\/wp-content\/uploads\/2023\/10\/51959a6d676e0ad5ee98884567dd49ec.png\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>Multe proiecte continu\u0103 s\u0103 utilizeze versiuni vulnerabile, de exemplu, 23% din desc\u0103rc\u0103rile pachetului Java Log4j reprezint\u0103 \u00een continuare versiuni cu vulnerabilit\u0103\u021bi critice, remediate \u00een 2021. \u00cen repositoarele Maven Central, aproximativ 12% din toate desc\u0103rc\u0103rile provin din componente care con\u021bin vulnerabilit\u0103\u021bi cunoscute. \u00cen medie, pentru toate repositoarele, propor\u021bia desc\u0103rc\u0103rilor versiunilor vechi de pachete, ce se \u00eencadreaz\u0103 \u00een categorii riscante (de exemplu, cu vulnerabilit\u0103\u021bi nerezolvate), este de 20% (\u00een 80% din cazuri se descarc\u0103 versiuni actualizate). \u00cen 96% din cazuri, desc\u0103rc\u0103rile de componente cu vulnerabilit\u0103\u021bi ar fi putut fi evitate, aleg\u00e2nd versiuni \u00een care problema a fost deja remediat\u0103.      <\/p>\n<p>O problem\u0103 considerabil\u0103 \u00een men\u021binerea securit\u0103\u021bii o constituie \u0219i asigurarea calit\u0103\u021bii proiectelor. \u00cen ecosistemele pentru limbajele Java \u0219i JavaScript exist\u0103 mari dificult\u0103\u021bi \u00een acest sens \u2014 \u00een ultimul an, \u00eentre\u021binerea a fost oprit\u0103 pentru fiecare al cincilea proiect (18,6%), prezent \u00een Maven Central \u0219i NPM, \u0219i \u00eentre\u021binut \u00een anul precedent. Din cele 1,176 milioane de proiecte analizate, prezente \u00een depozitele Maven, NPM, PyPi \u0219i NuGet, doar 11% (118 mii) continu\u0103 s\u0103 fie \u00eentre\u021binute activ.       <\/p>\n<p>\u00cen cadrul studiului a fost realizat \u0219i un sondaj cu 621 de dezvoltatori profesionisti din diverse companii. 67% dintre responden\u021bi consider\u0103 c\u0103 aplica\u021biile lor nu folosesc biblioteci vulnerabile, 10% s-au confruntat \u00een ultimele 12 luni cu incidente de securitate cauzate de vulnerabilit\u0103\u021bi \u00een software-ul open-source, iar 20% au avut dificult\u0103\u021bi \u00een a r\u0103spunde. 28% dintre companii identific\u0103 prezen\u021ba componentelor vulnerabile \u00een termen de 1 zi de la dezv\u0103luirea informa\u021biilor despre vulnerabilitate, 39% \u2014 \u00eentre 1 \u0219i 7 zile, iar 29% \u2014 mai mult de o s\u0103pt\u0103m\u00e2n\u0103.<br \/>\n<br \/>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59936\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Sonatype, \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u044e\u0449\u0430\u044f\u0441\u044f \u043d\u0430 \u0437\u0430\u0449\u0438\u0442\u0435 \u043e\u0442 \u0430\u0442\u0430\u043a, \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u043f\u043e\u0434\u043c\u0435\u043d\u043e\u0439 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u043e\u0432 \u0438 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0435\u0439 (supply chain), \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f (PDF, 62 \u0441\u0442\u0440.) \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u043c\u0438 \u0438 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0435\u043d\u0438\u0435\u043c \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432 \u043d\u0430 \u044f\u0437\u044b\u043a\u0430\u0445 Java, JavaScript, Python \u0438 .NET, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 Maven Central, NPM, PyPl \u0438 Nuget. \u0417\u0430 \u0433\u043e\u0434 \u043e\u0442\u043c\u0435\u0447\u0435\u043d\u043e \u0443\u0432\u0435\u043b\u0438\u0447\u0435\u043d\u0438\u0435 \u0447\u0438\u0441\u043b\u0430 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432 \u0432 \u043e\u0442\u0441\u043b\u0435\u0436\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u044d\u043a\u043e\u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":110894,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-110893","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Sonatype, \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u044e\u0449\u0430\u044f\u0441\u044f \u043d\u0430 \u0437\u0430\u0449\u0438\u0442\u0435 \u043e\u0442 \u0430\u0442\u0430\u043a, \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u043f\u043e\u0434\u043c\u0435\u043d\u043e\u0439 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u043e\u0432 \u0438 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0435\u0439 (supply chain), \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f (PDF, 62 \u0441\u0442\u0440.) \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u043c\u0438 \u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/oczenka-problem-s-soprovozhdeniem-otkrytyh-proektov-i-ispolzovaniem-staryh-zavisimostej\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u0446\u0435\u043d\u043a\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0435\u043d\u0438\u0435\u043c \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u0441\u0442\u0430\u0440\u044b\u0445 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Sonatype, \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u044e\u0449\u0430\u044f\u0441\u044f \u043d\u0430 \u0437\u0430\u0449\u0438\u0442\u0435 \u043e\u0442 \u0430\u0442\u0430\u043a, \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u043f\u043e\u0434\u043c\u0435\u043d\u043e\u0439 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u043e\u0432 \u0438 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0435\u0439 (supply chain), \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f (PDF, 62 \u0441\u0442\u0440.) \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u043c\u0438 \u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/oczenka-problem-s-soprovozhdeniem-otkrytyh-proektov-i-ispolzovaniem-staryh-zavisimostej\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-10-17T07:10:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-10-17T07:10:19+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Evaluarea problemelor legate de \u00eentre\u021binerea proiectelor open-source \u0219i utilizarea dependen\u021belor \u00eenvechite | ProHoster","description":"Compania Sonatype, specializat\u0103 \u00een protec\u021bia \u00eempotriva atacurilor de manipulare a componentelor software \u0219i a dependen\u021belor (supply chain), a publicat rezultatele unei cercet\u0103ri (PDF, 62 pag.) cu privire la problemele legate de dependen\u021be \u0219i.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/oczenka-problem-s-soprovozhdeniem-otkrytyh-proektov-i-ispolzovaniem-staryh-zavisimostej","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u0446\u0435\u043d\u043a\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0435\u043d\u0438\u0435\u043c \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432 \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u0441\u0442\u0430\u0440\u044b\u0445 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Sonatype, \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0437\u0438\u0440\u0443\u044e\u0449\u0430\u044f\u0441\u044f \u043d\u0430 \u0437\u0430\u0449\u0438\u0442\u0435 \u043e\u0442 \u0430\u0442\u0430\u043a, \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u043f\u043e\u0434\u043c\u0435\u043d\u043e\u0439 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u043e\u0432 \u0438 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0435\u0439 (supply chain), \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f (PDF, 62 \u0441\u0442\u0440.) \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u043c\u0438 \u0438.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/oczenka-problem-s-soprovozhdeniem-otkrytyh-proektov-i-ispolzovaniem-staryh-zavisimostej","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-10-17T07:10:19+00:00","article:modified_time":"2023-10-17T07:10:19+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/110893","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=110893"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/110893\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media\/110894"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=110893"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=110893"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=110893"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}