upload/duxiu_main2/【星空藏书馆】/【星空藏书馆】等多个文件/图书馆8号/市场研报/市场研究报告/20年/8月份精选报告/8月份第4周精选报告/extracted__精选行业报告(134份).zip/sonatype-2020年软件供应链状况报告(英文)-2020.8-44页.pdf
sonatype-2020年软件供应链状况报告(英文)-2020.8-44页.pdf 🔍
Adobe InDesign 15.1 (Macintosh)
PDF · 8.1MB · 📗 未知类型的图书 · 🚀/upload · Save
描述
Introduction 4
CHAPTER 1 5
Open Season on Open Source 5
Software Supply Chain Attacks: Past and Future 6
Rise of Next-Gen Software Supply Chain Attacks (2015-2020) 7
Speed Remains Critical When Responding to Legacy Software Supply Chain Attacks 10
CHAPTER 2 12
Open Source: Supply and Demand 12
JavaScript 13
Java 14
.NET 14
DockerHub 14
Chapter 3 15
Identifying Exemplary Open Source Suppliers 15
Researching the Best Performing OSS Projects 16
Finding Different Behavioral Groups 16
Exemplars 16
Laggards 17
Cautious Teams 17
Projects with Updated Dependencies Are More Secure 18
Guidance for Open Source Project Owners and Contributors 19
Guidance for Enterprise Development Teams 19
Chapter 4 20
How High Performance Teams Manage Open Source Software Supply Chains 20
Survey of Open Source Management Practices 21
Comparing High Performers vs. Low Performers 23
Comparing High Performers vs. Security First 23
Variables Most Impacting Performance and Risk Management 24
Influencing Risk Management Outcomes 24
Influencing Productivity Outcomes 26
Influencing Job Satisfaction 27
Guidance for Enterprise Development Teams 27
Patterns Across OSS Component Updates: Easy, Difficult, and Planned 28
Chapter 5 31
The Trust and Integrity of Software Supply Chains 31
1 in 10 OSS Downloads Are Vulnerable 32
Enterprises Rely on Code from 3,500 Suppliers, But Quality Varies 33
OSS Components Make Up 90% of a Modern Application 33
21% of Enterprises Experienced Open Source Breaches 34
Chapter 6 35
The Changing OSS Landscape: Social Activism and Government Standards 35
Social Activism and Open Source Software 36
Governments Apply New Standards to Secure Software Supply Chains 36
United States 36
United Kingdom 38
Australia 39
Summary 40
Sources 41
Appendix A 42
Appendix B 43
CHAPTER 1 5
Open Season on Open Source 5
Software Supply Chain Attacks: Past and Future 6
Rise of Next-Gen Software Supply Chain Attacks (2015-2020) 7
Speed Remains Critical When Responding to Legacy Software Supply Chain Attacks 10
CHAPTER 2 12
Open Source: Supply and Demand 12
JavaScript 13
Java 14
.NET 14
DockerHub 14
Chapter 3 15
Identifying Exemplary Open Source Suppliers 15
Researching the Best Performing OSS Projects 16
Finding Different Behavioral Groups 16
Exemplars 16
Laggards 17
Cautious Teams 17
Projects with Updated Dependencies Are More Secure 18
Guidance for Open Source Project Owners and Contributors 19
Guidance for Enterprise Development Teams 19
Chapter 4 20
How High Performance Teams Manage Open Source Software Supply Chains 20
Survey of Open Source Management Practices 21
Comparing High Performers vs. Low Performers 23
Comparing High Performers vs. Security First 23
Variables Most Impacting Performance and Risk Management 24
Influencing Risk Management Outcomes 24
Influencing Productivity Outcomes 26
Influencing Job Satisfaction 27
Guidance for Enterprise Development Teams 27
Patterns Across OSS Component Updates: Easy, Difficult, and Planned 28
Chapter 5 31
The Trust and Integrity of Software Supply Chains 31
1 in 10 OSS Downloads Are Vulnerable 32
Enterprises Rely on Code from 3,500 Suppliers, But Quality Varies 33
OSS Components Make Up 90% of a Modern Application 33
21% of Enterprises Experienced Open Source Breaches 34
Chapter 6 35
The Changing OSS Landscape: Social Activism and Government Standards 35
Social Activism and Open Source Software 36
Governments Apply New Standards to Secure Software Supply Chains 36
United States 36
United Kingdom 38
Australia 39
Summary 40
Sources 41
Appendix A 42
Appendix B 43
备用文件名
upload/duxiu_main2/【星空藏书馆】/【星空藏书馆】等多个文件/图书馆8号/市场研报/各大细分行业研报资料/计算机软件/extracted__计算机软件行业(2020年1-10月,110份).zip/sonatype-2020年软件供应链状况报告(英文)-2020.8-44页.pdf
元数据中的注释
producers:
Adobe PDF Library 15.0
Adobe PDF Library 15.0
开源日期
2025-01-15
🚀 快速下载
成为会员以支持书籍、论文等的长期保存。为了感谢您对我们的支持,您将获得高速下载权益。❤️
如果您在本月捐款,您将获得双倍的快速下载次数。
🐢 低速下载
由可信的合作方提供。 更多信息请参见常见问题解答。 (可能需要验证浏览器——无限次下载!)
- 低速服务器(合作方提供) #1 (稍快但需要排队)
- 低速服务器(合作方提供) #2 (稍快但需要排队)
- 低速服务器(合作方提供) #3 (稍快但需要排队)
- 低速服务器(合作方提供) #4 (稍快但需要排队)
- 低速服务器(合作方提供) #5 (无需排队,但可能非常慢)
- 低速服务器(合作方提供) #6 (无需排队,但可能非常慢)
- 低速服务器(合作方提供) #7 (无需排队,但可能非常慢)
- 低速服务器(合作方提供) #8 (无需排队,但可能非常慢)
- 低速服务器(合作方提供) #9 (无需排队,但可能非常慢)
- 下载后: 在我们的查看器中打开
所有选项下载的文件都相同,应该可以安全使用。即使这样,从互联网下载文件时始终要小心。例如,确保您的设备更新及时。
外部下载
-
对于大文件,我们建议使用下载管理器以防止中断。
推荐的下载管理器:JDownloader -
您将需要一个电子书或 PDF 阅读器来打开文件,具体取决于文件格式。
推荐的电子书阅读器:Anna的档案在线查看器、ReadEra和Calibre -
使用在线工具进行格式转换。
推荐的转换工具:CloudConvert和PrintFriendly -
您可以将 PDF 和 EPUB 文件发送到您的 Kindle 或 Kobo 电子阅读器。
推荐的工具:亚马逊的“发送到 Kindle”和djazz 的“发送到 Kobo/Kindle” -
支持作者和图书馆
✍️ 如果您喜欢这个并且能够负担得起,请考虑购买原版,或直接支持作者。
📚 如果您当地的图书馆有这本书,请考虑在那里免费借阅。
下面的文字仅以英文继续。
总下载量:
“文件的MD5”是根据文件内容计算出的哈希值,并且基于该内容具有相当的唯一性。我们这里索引的所有影子图书馆都主要使用MD5来标识文件。
一个文件可能会出现在多个影子图书馆中。有关我们编译的各种数据集的信息,请参见数据集页面。
有关此文件的详细信息,请查看其JSON 文件。 Live/debug JSON version. Live/debug page.