IT Briefcase Exclusive Interview: Getting the Most Out of Open Source While Managing License Compliance, Risk, and Security

Mar 4, 2020 | App Modernization, Cloud, Data, Fresh Ink, Inside the Briefcase, Privacy, Security, Social Media

open source - pc board

In this interview, Kendra Morton, product marketing manager at Flexera, discusses Software Composition Analysis (SCA) trends including leading Flexera’s annual State of Open Source License Compliance report.

  • Q. Open source software (OSS) is widely used. What are some top concerns about how an enterprise deploys it?

A. Open source software provides very real benefits and conveniences. It helps increase productivity, improves time to market, and can provide lower cost solutions. It is no more or less secure than proprietary code; each has weaknesses. Open source management is really about creating a well-defined open source strategy and empowering organizations to continue to successfully leverage open source now and in the future. While it is cost-free, it comes with licensing and copyright responsibilities.

Organizations must understand the structural quality of all third-party software used in applications and their dependencies—likely thousands of them. This requires understanding your supply chain, how partners use OSS, entry points (such as containers), graphic libraries, and more. Each carry intellectual property (IP) and need to be accounted for in a complete, accurate, and current inventory: a software bill of materials (BOM). As open source becomes more pervasive, the possibility for risk increases.

  • Q. How aware are organizations about their open source use?

A. Awareness is key—and lacking. The 2020 State of Open Source License Compliance report from Flexera analyzed data from 121 audit projects to determine how much open source is being used, what companies are aware of in terms of use, and the number of license compliance issues and vulnerabilities that exist in their applications.

Of the scanned codebase files, 45% were attributed to open source components. Only 1% of the issues uncovered were disclosed prior to audit start. Among the security vulnerabilities that the research uncovered, 45% contained a “high” Common Vulnerability Scoring System (CVSS) risk score. Highest severity issues include strong Copyleft compliances involving the APGL and GPL or other important vulnerabilities; these should be remediated immediately, as they represent critical IP security threats. In an age when security breaches make headline after headline, companies can’t leave vulnerabilities unchecked.

These concerns apply across the board and in a wide range of verticals. Enterprises that embed software into a device or financials, that develop apps, ship products to customers or that host applications that expose private or financial information must take precautions around OSS.

  • Q. What’s needed to ensure compliance with open source software licenses?

A. In short, vigilance. As enterprises move to be more agile, legal, risk, and development teams must ensure that they’re using safe versions of open source software. Continuous scanning and monitoring throughout the software development lifecycle (SDLC) is crucial. Software Composition Analysis (SCA)—an automated process for discovering and managing risk, security, and compliance—helps organizations leverage OSS safely.

The goals are to manage license compliance, IP, and security risks; maintain code quality and data integrity; and provide transparency and complete visibility into use of open source for stakeholders, executives, partners, and customers. With processes in place for these, it becomes possible to remediate issues quickly and expertly, while minimizing future occurrences.

  • Q. What are the elements of software composition analysis (SCA)?

A. Software Composition Analysis is the process of automating the visibility into open source software (OSS) use for the purpose of license compliance, risk management, and security. SCA enables secure risk management of OSS through the supply chain in a number of ways. It scans for license compliance and security vulnerabilities in existing BOM items; provides an accurate, complete BOM for all applications; discovers and tracks all open source; enables a clear, effective path for issue remediation; and provides proactive, continuous open source monitoring. These elements support an organization’s strategy for setting and enforcing policies, while seamlessly integrating code scanning into the build environment.

SCA scans can take different forms. Standard audit analyses identify the top priority (P1) licenses and significantly large third-party components; evidence types included here are explicit P1 licenses, copyrights, exact matches, and binary files. Forensic audit analyses go deeper and find more issues per project; these in-depth, deep level scans examine all evidence types, including emails/URLs, expanded search terms, and source code snippet matches. Targeted audit analyses are customized to meet aggressive timelines, budgetary needs, or target specific areas of the codebase. All scans help prioritize issues, with the goal of creating plans for resolution of those concerns.

  • Q. How can companies move forward with their efforts to understand their OSS use and minimize the associated risk?

A. First, have clear company license and security policies. Establishing an Open Source Review Board (OSRB)—with members from your legal, engineering, and product management team—can help put policies in place and create a reporting structure. Establish stakeholder training to ensure that all parties understand expectations and have a shared knowledge of the organizational risk spectrum. Implement an automated software monitoring and scanning solution, which streamlines and improves the process. Also create vendor programs to better manage third-party and supply chain requirements.

When issues are found, begin remediation. Start with the highest priority, then work through remaining issues. The process is worth it—for you and for the customers who rely on your product.

laaaady

Kendra Morton, product marketing manager at Flexera, conducts research on Software Composition Analysis (SCA) trends including leading Flexera’s annual State of Open Source License Compliance report. Before joining Flexera, Morton spent more than 15 years at Teradata in a variety of marketing and demand generation roles.

 

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more
Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

July 24, 2026 | ITBriefcase.net Why it matters: OpenAI disclosed on July 21 that two of its AI models — GPT-5.6 Sol and an unnamed, more capable pre-release model — autonomously escaped an internal evaluation sandbox while being tested against the ExploitGym...

read more