AI智能总结![[分析レポート] 2023年オープンソース・セキュリティ&リスク分析レポート | シノプシス](https://public.fxbaogao.com/report-image/2023/10/17/4081360-1.png?x-oss-process=image/crop,x_0,y_0,w_1980,h_2800/resize,p_60)
[] []...............................................................................................................................................................32023&CyRC...............................................................3[] ....................................................................................................................................................................42022.....................................................................................................................4.................................................................................................................5......................................................................................................................................................................6[] ..............................................................................................................................................7.....................................................................................................................7....................................8..............................................................................................................................................95.................................................................................................................................................11 [] ..........................................................................................................................................................13 ...................................................................................................................................13................................................................................................................................14[] ...............................................................................................................................15............................................................................................................15...........................................................................................................................................16...........................................................................................................17[] ................................................................................................................................................................18................................................................................................................................18.............................................................................................................................................18SBOM................................................................................................................................................18 [] Black Duck®SCACyRC20Black Duck SCAM&ABlack DuckBlack DuckwebAPISBOMBlack Duck KnowledgeBase ™Black DuckKnowledgeBase28,000CyRC610 2023&CyRC 20238&OSSRACyRCCyRC OSSRA OSSRACyRC202320222022CyRC171,700CyRCM&A2022M&A OSSRA [] 20221,70387%/ 1 2 [] SBOMSBOMEO 140281 Apache Log4j2BDSA-2021-3887CVE-2021-44228Apache Log4j2Log4jJavaLog4jRCEDoSLDAP Black Duck Security AdvisoryBDSA CyRCBDSA/BDSANationalVulnerability DatabaseNVD:BDSA SCA SCA OpenSSL 202211OpenSSLCritical2CVE-2022-3602CVE-2022-3786High/ SBOM SCANTIASBOMSBOMSPDXSoftware Package Data ExchangeCycloneDX2 1 / / EO 14028 20215Improving the Nation's CybersecurityEO14028 2 2023&| ©2023 Synopsys, Inc. [] Black Duck1,70396%76%76% 1595SCA 184%2022OSSRA4%48%2% Black Duck2023Black Duck1,70387%1,481/2023OSSRA1,4811,703 [] Enterprise Strategy GroupESGGitOps73%1234% EO 140282 2025 [] //92% ////100%73%63%7 /78%69%95% [] SVSSBlack Duck Security AdvisoryBDSABDSAFIRST.orgCVSSCVSSSVSSNVDCyRCBDSACVSSNVDBDSA [] 5 OSSRA5 1 592%5 20182022163%////97%//74% ////22% [] /Joe Jarzombek1CMMCJarzombek SaaSISV 5 +557%/ e IoTInternet of Things2020100%201835%89%IoTRingAmazon NestIoT 2 201842%/e2018557% IoT2018130%53%IoTIoTIoT ////232% 1SaaSUSB +232%//// [] Black Duck202254%2%202065%17% Creative CommonsShareAlike 3.0CC BY-SA 3.022%CC BY-SA 3.0 Black Duck85%Q&AStackOverflowStack OverflowCC BY-SA 3.0SaaS /93%75%IoT78% [] GNU General Public LicenseGPLGPL 202255%31%211 GitHubweb IPJSONJSONMITM&AJSON [] LinuxBlack Duckp.71,48122491% Kubernetes MicrosoftRedHatGoogle [] TwitterWill NorrisTwitterTwitter Consortium for Information and Software QualityCISQ2022IoTOT Twitter 2022npmJavaScriptNode.jswebIcon-packageIonicioAjax-libs npm 51 91%88%2472%2415%11 [] Log4j Black Duckp.71,48191% 1Log4Shell5%Log4jJava11% DevSecOps Log4jLog4jLog4jLog4j SBOMLog4Shell 91%DevSecOps Log4j Log4jJava [] SBOM SBOMSBOMBOMBOMSBOMBOMSBOMSBOM •GitOps•M&A Activity Looks Anemic Heading to Year-End asLBOs Shrivel•Global M&A market slows in 2022 first halfbut showssigns of str