Organizations running their business on open source software are faced with a more aggressive and complicated security and compliance landscape than ever before. Malicious actors are bypassing transitional security tools by directly targeting developers, according to Sonatype’s10th annual “State of the Software Supply Chain” report. The number of malicious packages logged in 2024 increased 156% year over year, the report says.
While the cloud native and DevOps movements of the past decade-plus have made progress in promoting the idea of…








