The nonprofit Linux Foundation in conjunction with Harvard’s Lab for Innovation Science recently published https://linuxfoundation.org/tools/census-ii-of-free-and-open-source-software-application-libraries/. Because software components are packaged, and versions are identified and cataloged in so many unstandardized ways, the report has organized them into eight Top 500 lists. As Mike McGuire, security solutions manager with the https://www.synopsys.com/software-integrity.html says, packages and versions are a bit like the different model, year and trim of a car.

“There are many indicators that could be used to suggest risk and different organizations may weight factors differently,” the authors wrote.

Still, measuring risk profiles is easier to do once the most widely used software is identified, the Census II authors wrote.

Related Articles