U-75% wezinhlelo zokusebenza zezentengiso zifaka phakathi ikhodi yomthombo ovulekile ephelelwe yisikhathi enobungozi

Inkampani ye-Synopsy kuhlaziywe 1253 amakhodi okuhweba okuhweba futhi aphethe ngokuthi cishe zonke (99%) zezicelo zentengiso ezibuyekeziwe zihlanganisa okungenani ingxenye eyodwa yomthombo ovulekile, futhi u-70% wekhodi kumakhosombe abuyekeziwe wawungumthombo ovulekile. Uma kuqhathaniswa, ocwaningweni olufanayo ngo-2015, isabelo somthombo ovulekile sasingama-36%.

Kodwa-ke, ezimweni eziningi, ikhodi yomthombo ovulekile yenkampani yangaphandle esetshenzisiwe ayibuyekezwa futhi iqukethe izinkinga zokuphepha ezingaba khona - u-91% wama-codebases abuyekeziwe anezingxenye ezivuliwe ezingazange zibuyekezwe iminyaka engaphezu kwengu-5 noma eziye zashiywa okungenani iminyaka emibili futhi ayinakekelwa onjiniyela. Njengomphumela, u-75% wekhodi yomthombo ovulekile ekhonjwe kumakhosombe aqukethe ubungozi obaziwayo obungakabhaliswa, uhhafu wabo onezinga eliphezulu lengozi. Kusampula yango-2018, isabelo sekhodi esinobungozi sasingu-60%.

Ubungozi obuvame kakhulu kwaba
inkinga I-CVE-2018-16487 (ukwenziwa kwekhodi yesilawuli kude) kulabhulali lodash ku-Node.js, izinguqulo ezisengozini okuhlangatshezwane nazo izikhathi ezingaphezu kuka-500. Ubungozi obudala obungapeyishiwe bekuyinkinga ku-lpd daemon (I-CVE-1999-0061), yabuyekezwa ngo-1999.

Ngaphezu kokuvikeleka ezisekelweni zekhodi zamaphrojekthi wezohwebo, kubuye kube nesimo sengqondo sokudebesela ngokuhambisana nemibandela yamalayisensi amahhala.
Ku-73% wama-codebases, izinkinga zitholwe ngokusemthethweni kokusebenzisa umthombo ovulekile, isibonelo, amalayisense angahambisani (imvamisa ikhodi ye-GPL ifakwe emikhiqizweni yokuhweba ngaphandle kokuvula umkhiqizo osuselwe) noma ukusetshenziswa kwekhodi ngaphandle kokucacisa ilayisense. Ama-93% azo zonke izinkinga zelayisensi zenzeka kuwebhu kanye nezinhlelo zokusebenza zeselula. Emidlalweni, izinhlelo ezingokoqobo ezibonakalayo, izinhlelo ze-multimedia nezokuzijabulisa, ukwephulwa kwaqashelwa ku-59% wamacala.

Sekukonke, ucwaningo luhlonze izingxenye ezivulekile eziyi-124 ezivame ukusetshenziswa kuzo zonke izisekelo zamakhodi. Ezidume kakhulu yilezi: jQuery (55%), Bootstrap (40%), Font Awesome (31%), Lodash (30%) kanye jQuery UI (29%). Mayelana nezilimi zokuhlela, ezidume kakhulu yiJavaScript (esetshenziswa kumaphrojekthi angama-74%), C++ (57%), Shell (54%), C (50%), Python (46%), Java (40%), I-TypeScript (36%), C# (36%); Perl (30%) kanye noRuby (25%). Isamba esiphelele sezilimi zokuhlela sithi:
I-JavaScript (51%), C++ (10%), Java (7%), Python (7%), Ruby (5%), Go (4%), C (4%), PHP (4%), TypeScript ( 4%), C# (3%), Perl (2%) kanye noShell (1%).

Source: opennet.ru

Engeza amazwana