4 Steps to Reduce Risks and Costs of Open Source Languages
May 29, 2019

Bart Copeland
ActiveState

It's become common practice to use open source languages to code, helping companies iterate and release more quickly in a DevOps world. However, these languages bring some challenges with them, adding complexity and risk. Developers are still wasting time on retrofitting languages to comply with enterprise criteria, according to ActiveState's annual developer survey.

The amount of time spent on programming has dropped almost 20% since last year. More than 61% of respondents spend just four hours or less per day programming — that is, actually doing their job. Developers aren't able to focus efforts on high-value work due to non-coding activities like retrofitting software for security and open source licenses after application software and languages have been built.


Another important finding is that 41% of enterprise IT departments experienced some or many problems ensuring that security is up to date with the latest or most secure version of every package. In addition, 40% experienced some or many problems building new, stable releases that behave the same as old releases.

These statistics speak to the fact that IT departments lack visibility into new security threats and struggle to track code in production for required updates, patches and new vulnerabilities. Development grabs from open source ecosystems, which consist of thousands of third-party packages that may or may not comply with enterprise security and open source license criteria. This, of course, can expose a company to application-level security vulnerabilities.

As for open source languages themselves, popularity and satisfaction aren't always connected. For daily use, developers most often use SQL (80%) — but Python has the highest satisfaction levels: 77% were satisfied or very satisfied with it.

Perhaps its satisfaction is owed to the fact that Python is quite flexible. It began as a scripting solution for sysadmins, then became useful to web development for programmers and is now the driving force behind machine learning. The language's usage continues to grow — developers clearly want to use it. So, to support this usage, organizations need to ensure their developers can do so safely and securely.

And for organizations to effectively decrease the risks and costs of managing open source languages they should implement a systematic and automated workflow: Open Source Language Automation. This workflow can be broken down into four steps:

1. Define Policies

Companies must set organization-wide open source language policies, version controls and triggers.

2. Centralize Dependencies

Track languages and packages across DevOps cycles to assess open source usage and ultimately produce a single source of truth for open source languages.

3. Automate Your Builds

Reduce vulnerabilities and increase application quality by automatically creating builds with a systematic, repeatable build process organization-wide.

4. Deploy and Manage Artifacts

Automatically update all test, stage and production servers with the appropriate and latest open source language builds.

Open source languages provide the flexibility developers are looking for, so they are here to stay in the enterprise. Using the four steps will help your organization continue to iterate quickly, but with greater efficiency and security.

Methodology: ActiveState surveyed 1,250 developers in 88 countries on what they're spending their work hours on and how they are using open source languages. Respondent ages ranged from under 25 to 61+ years, with those in their early 40s making up the largest group at almost 15%. The largest number of responses came from the U.S., Canada and Germany.

Bart Copeland is CEO and President of ActiveState
Share this

Industry News

May 08, 2024

MacStadium announced that it has obtained Cloud Security Alliance (CSA) Security, Trust & Assurance Registry (STAR) Level 1, meaning that MacStadium has publicly documented its compliance with CSA’s Cloud Controls Matrix (CCM), and that it joined the Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment.

May 08, 2024

The Cloud Native Computing Foundation® (CNCF®) released the two-day schedule for CloudNativeSecurityCon North America 2024 happening in Seattle, Washington from June 26-27, 2024.

May 08, 2024

Sumo Logic announced new AI and security analytics capabilities that allow security and development teams to align around a single source of truth and collect and act on data insights more quickly.

May 08, 2024

Red Hat is announcing an optional additional 12-month EUS term for OpenShift 4.14 and subsequent even-numbered Red Hat OpenShift releases in the 4.x series.

May 08, 2024

HAProxy Technologies announced the launch of HAProxy Enterprise 2.9.

May 08, 2024

ArmorCode announced the general availability of AI Correlation in the ArmorCode ASPM Platform.

May 08, 2024

Octopus Deploy launched new features to help simplify Kubernetes CD at scale for enterprises.

May 08, 2024

Cequence announced multiple ML-powered advancements to its Unified API Protection (UAP) platform.

May 07, 2024

Oracle announced plans for Oracle Code Assist, an AI code companion, to help developers boost velocity and enhance code consistency.

May 07, 2024

New Relic launched Secure Developer Alliance.

May 07, 2024

Dynatrace is enhancing its platform with new Kubernetes Security Posture Management (KSPM) capabilities for observability-driven security, configuration, and compliance monitoring.

May 07, 2024

Red Hat announced advances in Red Hat OpenShift AI, an open hybrid artificial intelligence (AI) and machine learning (ML) platform built on Red Hat OpenShift that enables enterprises to create and deliver AI-enabled applications at scale across hybrid clouds.

May 07, 2024

ServiceNow is introducing new capabilities to help teams create apps and scale workflows faster on the Now Platform and to boost developer and admin productivity.

May 06, 2024

Red Hat and Oracle announced the general availability of Red Hat OpenShift on Oracle Cloud Infrastructure (OCI) Compute Virtual Machines (VMs).

May 06, 2024

The Software Engineering Institute at Carnegie Mellon University announced the release of a tool to give a comprehensive visualization of the complete DevSecOps pipeline.