75% ea lits'ebetso tsa khoebo e kenyelletsa khoutu ea khale ea mohloli o bulehileng o nang le bofokoli

Khampani ea Synopsys hlahlobisitsoe 1253 khoebo codebases 'me a etsa qeto ea hore hoo e ka bang tsohle (99%) ea dikopo tsa khoebo hlahlobiloeng e kenyelelitse bonyane karolo e le' ngoe e bulehileng mohloli, 'me 70% ea khoutu ka lipolokelong hlahlojoa e ne e le mohloli o bulehileng. Ha ho bapisoa, phuputsong e tšoanang ka 2015, karolo ea mohloli o bulehileng e ne e le 36%.

Leha ho le joalo, maemong a mangata, khoutu ea mohloli o bulehileng oa motho oa boraro e sebelisitsoeng ha e ntlafatsoe ebile e na le mathata a ka bang teng ts'ireletso - 91% ea li-codebases tse hlahlobiloeng li na le likarolo tse bulehileng tse sa kang tsa ntlafatsoa ka lilemo tse fetang 5 kapa tse seng li le ka mokhoa o lahliloeng. bonyane lilemo tse peli 'me ha li hlokomeloe ke bahlahisi. Ka lebaka leo, 75% ea khoutu ea mohloli o bulehileng e bonts'itsoeng libakeng tsa polokelo e na le bofokoli bo sa tsejoeng, 'me halofo ea bona e na le kotsi e kholo. Mohlala oa 2018, karolo ea khoutu e nang le bofokoli e ne e le 60%.

Bofokoli bo neng bo atile haholo bo ne bo le kotsi
bothata CVE-2018-16487 (remote code execution) ka laeboraring lodash bakeng sa Node.js, liphetolelo tse tlokotsing li ile tsa kopana le makhetlo a fetang 500. Kotsi ea khale ka ho fetesisa e sa ngolisoang e bile bothata ho lpd daemon (CVE-1999-0061), e ntlafalitsoeng ka 1999.

Ntle le ts'ireletso metheong ea khoutu ea merero ea khoebo, ho boetse ho na le maikutlo a bohlasoa mabapi le ho latela lipehelo tsa li-license tsa mahala.
Ho 73% ea li-codebases, mathata a ile a fumanoa ka molao oa ho sebelisa mohloli o bulehileng, mohlala, li-license tse sa lumellaneng (hangata khoutu ea GPL e kenyelelitsoe lihlahisoa tsa khoebo ntle le ho bula sehlahisoa se nkiloeng) kapa tšebeliso ea khoutu ntle le ho bolela lengolo la tumello. 93% ea mathata ohle a laesense a hlaha lits'ebetsong tsa marang-rang le tsa mehala. Lipapaling, mekhoa ea sebele ea sebele, mananeo a multimedia le boithabiso, tlōlo ea molao e ile ea hlokomeloa ho 59% ea linyeoe.

Ka kakaretso, phuputso e fumane likarolo tse 124 tse tloaelehileng tse bulehileng tse sebelisoang hangata metheong eohle ea khoutu. Tse tsebahalang haholo ke: jQuery (55%), Bootstrap (40%), Font Awesome (31%), Lodash (30%) le jQuery UI (29%). Mabapi le lipuo tsa mananeo, tse tsebahalang haholo ke JavaScript (e sebelisoang ho 74% ea merero), C++ (57%), Shell (54%), C (50%), Python (46%), Java (40%), TypeScript (36%), C # (36%); Perl (30%) le Ruby (25%). Kabelo eohle ea lipuo tsa lenaneo ke:
JavaScript (51%), C++ (10%), Java (7%), Python (7%), Ruby (5%), Go (4%), C (4%), PHP (4%), TypeScript ( 4%), C# (3%), Perl (2%) le Shell (1%).

Source: opennet.ru

Eketsa ka tlhaloso