75% yezvishandiso zvekutengesa zvinosanganisira yekare yakavhurika sosi kodhi ine ngozi

Synopsys Company analysed 1253 yekutengesa macodebases uye yakagumisa kuti inenge yese (99%) yezvikumbiro zvekutengesa zvakaongororwa zvaisanganisira chikamu chimwe chete chakazaruka, uye 70% yekodhi muzvinyorwa zvakaongororwa yakanga yakazaruka. Kuenzanisa, mune chidzidzo chakafanana muna 2015, mugove wekuvhura sosi yaive 36%.

Nekudaro, kazhinji, iyo yechitatu-bato yakavhurika sosi kodhi yakashandiswa haina kuvandudzwa uye ine zvingangoitika matambudziko ekuchengetedza - 91% yecodebases yakaongororwa ine zvikamu zvakavhurika izvo zvisina kuvandudzwa kweanopfuura makore 5 kana kuti anga ari mufomu yakasiiwa. angangoita makore maviri uye haachengetwe nevagadziri. Nekuda kweizvozvo, 75% yeakavhurika sosi kodhi yakaonekwa mumarepositori ine isina kunyorwa inozivikanwa kusagadzikana, hafu ine ngozi yakanyanya. Mumuenzaniso we 2018, chikamu chekodhi chine hurema chaive 60%.

Kusagadzikana kwakanyanya kune ngozi kwaive
dambudziko CVE-2018-16487 (remote code execution) muraibhurari lodash yeNode.js, vhezheni dzisina njodzi dzakasangana nekanopfuura ka500. Kusagadzikana kwekare kusingaverengeki raive dambudziko mulpd daemon (CVE-1999-0061), yakadzokororwa muna 1999.

Pamusoro pekuchengetedzeka mumabhesi ekodhi emapurojekiti ekutengesa, kune zvakare maitiro ekuregeredza kune kutevedzera zvirevo zvemahara marezinesi.
Mu73% yekodhibases, matambudziko akawanikwa nemutemo wekushandisa yakavhurika sosi, semuenzaniso, marezinesi asingaenderane (kazhinji GPL kodhi inosanganisirwa mune zvekutengesa zvigadzirwa pasina kuvhura inobuda chigadzirwa) kana kushandiswa kwekodhi pasina kutsanangura rezinesi. 93% yematambudziko ese rezinesi anoitika muwebhu uye nharembozha. Mumitambo, masystem chaiwo, multimedia uye zvirongwa zvekuvaraidza, kutyorwa kwakaonekwa mu59% yezviitiko.

Pakazara, chidzidzo chakaratidza 124 zvakajairika zvikamu zvakavhurika izvo zvinowanzoshandiswa mumabhesi ese ekodhi. Anonyanya kufarirwa ndeaya: jQuery (55%), Bootstrap (40%), Font Awesome (31%), Lodash (30%) uye jQuery UI (29%). Panyaya yemitauro yekuronga, inonyanya kufarirwa iJavaScript (inoshandiswa mu74% yemapurojekiti), C++ (57%), Shell (54%), C (50%), Python (46%), Java (40%), TypeScript (36%), C# (36%); Perl (30%) uye Ruby (25%). Iyo yakazara chikamu chemitauro yepurogiramu ndeiyi:
JavaScript (51%), C++ (10%), Java (7%), Python (7%), Ruby (5%), Go (4%), C (4%), PHP (4%), TypeScript ( 4%), C# (3%), Perl (2%) uye Shell (1%).

Source: opennet.ru

Voeg