Open source code can also be open risk

Issue 3 2025 Information Security, Infrastructure

Software development has fundamentally changed over the years. Agile approaches, rapid release cycles, and DevOps culture have transformed how software is created and released. However, amid this changing environment, one truth has gradually emerged: open-source code is increasingly forming the basis of modern applications. Estimates based on surveys indicate that 60 – 90% of the average application's code base consists of open-source components. It is not a factor of convenience, it is a necessity for innovation, speed, and economic viability, but with all the big adoption, there comes an admittedly under-recognised truth: open source introduces risk.

The question is not whether you are using open-source code, but rather whether you are doing it in a practical and managed way. That is where Debricked, a company within OpenText, comes into the picture. Debricked is becoming an essential solution in the modern secure software development lifecycle. Below, I explore why that is the case.


Wehann-Kritzinger.

The open source problem no one is talking about

Despite the many benefits of open-source software, it raises unique problems that most organisations would rather ignore:

Lack of transparency: Most projects have no complete list of all their open-source components.

Security vulnerabilities: Open-source packages may contain known Common Vulnerabilities and Exposures (CVEs). If these vulnerabilities are publicly disclosed but not yet patched or mitigated, they present an opportunity for attackers to exploit them during this window of exposure

License compliance: Failure to comply with open-source licenses (e.g., GNU General Public License (GPL), Massachusetts Institute of Technology (MIT), or Apache) would mean costly legal problems.

Abandonware risk: The vast majority of packages are unmaintained or inactive, rendering them a liability when bugs infiltrate or exploits take place.

These are not abstract concerns; they have real-world implications. Examples include the infamous Log4j vulnerability and attacks on software supply chains, such as the SolarWinds breach. Essentially, the consequences of uncontrolled open-source use are history.

Demystifying open source

Debricked is designed to help development, security, and legal teams make improved, faster, and safer open-source code choices. It achieves this by providing a collection of features that address the threats and inefficiencies associated with wild open-source usage.

1. Automatic software bill of materials (SBOM) generation.

An SBOM is an exhaustive list of all open-source components within an application. Debricked does this work automatically, so that teams understand what they are using — and where. It supports multiple package managers and languages, connects directly with CI/CD pipelines and repositories, and provides real-time insight into your software supply chain.

2. Machine-learning powered CVE scoring.

Not all vulnerabilities are the same. Some are theoretical, others are in use right now. Debricked uses machine learning models to score and rank CVEs by exploitability and real-world risk, allowing security teams to focus on threats that require attention. It removes noise and false positives, helps prioritise patching of large codebases, and automatically refreshes as new threats are found.

3. Licence compliance and legal risk mitigation.

Debricked scans all open-source modules and alerts on license types that are not compatible with your business model. This is necessary to prevent legal exposure and to safeguard intellectual property rights.

It flags incompatible or risky licences, such as copyleft licenses (e.g., GPL, LGPL), which require that derivative works or modifications of the original code be distributed under the same licence. In this manner, the code and any enhancements to the code remain open and freely available. It also delivers actionable, clear licence compliance findings and assists legal and compliance teams with audit-ready reporting.

4. Open-Source Health Metrics.

Would you build your business on software that is no longer maintained? Debricked provides an overview of the health and activity level of all packages you are using, including community engagement, frequency of updates, release history, issue tracker activity, and red flags for packages on the verge of abandonment.

This enables developers to make better decisions when selecting dependencies and reduces long-term technical debt.

One complete security solution

While Debricked excels at managing open-source components, applications are often built on custom code as well. That is where Fortify, another OpenText offering, comes in, offering end-to-end static, dynamic, and mobile application security testing (SAST, DAST, MAST). With this two-pronged solution, your entire code set — both proprietary and third-party — is safeguarded, tracked, and governed with minimal impact on developer productivity.

Why it matters more than ever today

As threats evolve and regulators ramp up compliance requirements, South African organisations—particularly those in the financial, healthcare, and public sectors — can no longer take open-source security and licence management at face value.

● POPIA and GDPR necessitate end-to-end accountability in the processing and securing of data.

● Banks are under greater scrutiny in terms of software supply chains and risk exposure.

● Product developers and teams need technology that does not constrain them, but facilitates secure, compliant innovation.

In an era where software underpins every facet of business, the strategic approach is to integrate security and governance into the process, rather than treating them as an afterthought.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Prompt injection is the new phishing
Information Security Security Services & Risk Management
AI security is heading in an uncomfortable direction following Microsoft’s research showing how prompt injection can be chained to remote code execution vulnerabilities in AI agent frameworks, including work involving Semantic Kernel

Read more...
Cloud-ready BMS is reshaping building operations
Facilities & Building Management Infrastructure
Buildings may be getting smarter, but too many control rooms are still anchored to yesterday’s technology, such as on-site servers, rigid architectures and a patchwork of interfaces that are expensive to run and slow to evolve.

Read more...
Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.