4 Steps to Reduce Risks and Costs of Open Source Languages
May 29, 2019

Bart Copeland
ActiveState

It's become common practice to use open source languages to code, helping companies iterate and release more quickly in a DevOps world. However, these languages bring some challenges with them, adding complexity and risk. Developers are still wasting time on retrofitting languages to comply with enterprise criteria, according to ActiveState's annual developer survey.

The amount of time spent on programming has dropped almost 20% since last year. More than 61% of respondents spend just four hours or less per day programming — that is, actually doing their job. Developers aren't able to focus efforts on high-value work due to non-coding activities like retrofitting software for security and open source licenses after application software and languages have been built.


Another important finding is that 41% of enterprise IT departments experienced some or many problems ensuring that security is up to date with the latest or most secure version of every package. In addition, 40% experienced some or many problems building new, stable releases that behave the same as old releases.

These statistics speak to the fact that IT departments lack visibility into new security threats and struggle to track code in production for required updates, patches and new vulnerabilities. Development grabs from open source ecosystems, which consist of thousands of third-party packages that may or may not comply with enterprise security and open source license criteria. This, of course, can expose a company to application-level security vulnerabilities.

As for open source languages themselves, popularity and satisfaction aren't always connected. For daily use, developers most often use SQL (80%) — but Python has the highest satisfaction levels: 77% were satisfied or very satisfied with it.

Perhaps its satisfaction is owed to the fact that Python is quite flexible. It began as a scripting solution for sysadmins, then became useful to web development for programmers and is now the driving force behind machine learning. The language's usage continues to grow — developers clearly want to use it. So, to support this usage, organizations need to ensure their developers can do so safely and securely.

And for organizations to effectively decrease the risks and costs of managing open source languages they should implement a systematic and automated workflow: Open Source Language Automation. This workflow can be broken down into four steps:

1. Define Policies

Companies must set organization-wide open source language policies, version controls and triggers.

2. Centralize Dependencies

Track languages and packages across DevOps cycles to assess open source usage and ultimately produce a single source of truth for open source languages.

3. Automate Your Builds

Reduce vulnerabilities and increase application quality by automatically creating builds with a systematic, repeatable build process organization-wide.

4. Deploy and Manage Artifacts

Automatically update all test, stage and production servers with the appropriate and latest open source language builds.

Open source languages provide the flexibility developers are looking for, so they are here to stay in the enterprise. Using the four steps will help your organization continue to iterate quickly, but with greater efficiency and security.

Methodology: ActiveState surveyed 1,250 developers in 88 countries on what they're spending their work hours on and how they are using open source languages. Respondent ages ranged from under 25 to 61+ years, with those in their early 40s making up the largest group at almost 15%. The largest number of responses came from the U.S., Canada and Germany.

Bart Copeland is CEO and President of ActiveState
Share this

Industry News

November 30, 2023

Parasoft, a global leader in automated software testing solutions, today announced complete support for MISRA C++ 2023 with the upcoming release of Parasoft C/C++test 2023.2.

November 30, 2023

Solo.io achieved the Amazon Elastic Kubernetes Service (Amazon EKS) Ready designation from Amazon Web Services (AWS).

November 29, 2023

CircleCI implemented a gen2 GPU resource class, leveraging Amazon Elastic Compute Cloud (Amazon EC2) G5 instances, offering the latest generation of NVIDIA GPUs and new images tailored for artificial intelligence/machine learning (AI/ML) workflows.

November 29, 2023

XM Cyber announced new capabilities that provide complete and continuous visibility into risks and vulnerabilities in Kubernetes environments.

November 29, 2023

PerfectScale has achieved the Amazon Elastic Kubernetes Service (Amazon EKS) Ready designation from Amazon Web Services (AWS).

November 28, 2023

BMC announced two new product innovations, BMC AMI DevX Code Insights and BMC AMI zAdviser Enterprise.

November 28, 2023

Rafay Systems announced the availability of the Rafay Cloud Automation Platform — the evolution of its Kubernetes Operations Platform — to enable platform teams to deliver automation and self-service capabilities to developers, data scientists and other cloud users.

November 28, 2023

Bitrise is integrating with Amazon Web Services (AWS) to provide compliance-conscious companies with greater access to CI/CD capabilities for mobile app development.

November 28, 2023

Armory announced a new unified declarative deployment capability for AWS Lambda.

November 27, 2023

Amazon Web Services (AWS) and Salesforce announced a significant expansion of their long standing, global strategic partnership, deepening product integrations across data and artificial intelligence (AI), and for the first time offering select Salesforce products on the AWS Marketplace.

November 27, 2023

Veracode announced product innovations to enhance the developer experience. The new features integrate security into the software development lifecycle (SDLC) and drive adoption of application security techniques in the environments where developers work.

November 27, 2023

Couchbase announced a new Capella columnar service on Amazon Web Services (AWS), enabling organizations to harness real-time analytics to build adaptive applications.

November 21, 2023

Redgate announced the launch of Redgate Test Data Manager, which simplifies the challenges that come with Test Data Management (TDM) and modern software development across multiple databases.

November 21, 2023

mabl announced an integration with GitLab, the AI-powered DevSecOps platform.

November 21, 2023

FusionAuth announced the availability of new software development kits (SDKs) that support Angular, React and Vue JavaScript front-end frameworks.