4 Steps to Reduce Risks and Costs of Open Source Languages
May 29, 2019

Bart Copeland
ActiveState

It's become common practice to use open source languages to code, helping companies iterate and release more quickly in a DevOps world. However, these languages bring some challenges with them, adding complexity and risk. Developers are still wasting time on retrofitting languages to comply with enterprise criteria, according to ActiveState's annual developer survey.

The amount of time spent on programming has dropped almost 20% since last year. More than 61% of respondents spend just four hours or less per day programming — that is, actually doing their job. Developers aren't able to focus efforts on high-value work due to non-coding activities like retrofitting software for security and open source licenses after application software and languages have been built.


Another important finding is that 41% of enterprise IT departments experienced some or many problems ensuring that security is up to date with the latest or most secure version of every package. In addition, 40% experienced some or many problems building new, stable releases that behave the same as old releases.

These statistics speak to the fact that IT departments lack visibility into new security threats and struggle to track code in production for required updates, patches and new vulnerabilities. Development grabs from open source ecosystems, which consist of thousands of third-party packages that may or may not comply with enterprise security and open source license criteria. This, of course, can expose a company to application-level security vulnerabilities.

As for open source languages themselves, popularity and satisfaction aren't always connected. For daily use, developers most often use SQL (80%) — but Python has the highest satisfaction levels: 77% were satisfied or very satisfied with it.

Perhaps its satisfaction is owed to the fact that Python is quite flexible. It began as a scripting solution for sysadmins, then became useful to web development for programmers and is now the driving force behind machine learning. The language's usage continues to grow — developers clearly want to use it. So, to support this usage, organizations need to ensure their developers can do so safely and securely.

And for organizations to effectively decrease the risks and costs of managing open source languages they should implement a systematic and automated workflow: Open Source Language Automation. This workflow can be broken down into four steps:

1. Define Policies

Companies must set organization-wide open source language policies, version controls and triggers.

2. Centralize Dependencies

Track languages and packages across DevOps cycles to assess open source usage and ultimately produce a single source of truth for open source languages.

3. Automate Your Builds

Reduce vulnerabilities and increase application quality by automatically creating builds with a systematic, repeatable build process organization-wide.

4. Deploy and Manage Artifacts

Automatically update all test, stage and production servers with the appropriate and latest open source language builds.

Open source languages provide the flexibility developers are looking for, so they are here to stay in the enterprise. Using the four steps will help your organization continue to iterate quickly, but with greater efficiency and security.

Methodology: ActiveState surveyed 1,250 developers in 88 countries on what they're spending their work hours on and how they are using open source languages. Respondent ages ranged from under 25 to 61+ years, with those in their early 40s making up the largest group at almost 15%. The largest number of responses came from the U.S., Canada and Germany.

Bart Copeland is CEO and President of ActiveState
Share this

Industry News

January 30, 2025

OutSystems announced the general availability (GA) of Mentor on OutSystems Developer Cloud (ODC).

January 30, 2025

Kurrent announced availability of public internet access on its managed service, Kurrent Cloud, streamlining the connectivity process and empowering developers with ease of use.

January 29, 2025

MacStadium highlighted its major enterprise partnerships and technical innovations over the past year. This momentum underscores MacStadium’s commitment to innovation, customer success and leadership in the Apple enterprise ecosystem as the company prepares for continued expansion in the coming months.

January 29, 2025

Traefik Labs announced the integration of its Traefik Proxy with the Nutanix Kubernetes Platform® (NKP) solution.

January 28, 2025

Perforce Software announced the launch of AI Validation, a new capability within its Perfecto continuous testing platform for web and mobile applications.

January 28, 2025

Mirantis announced the launch of Rockoon, an open-source project that simplifies OpenStack management on Kubernetes.

January 28, 2025

Endor Labs announced a new feature, AI Model Discovery, enabling organizations to discover the AI models already in use across their applications, and to set and enforce security policies over which models are permitted.

January 27, 2025

Qt Group is launching Qt AI Assistant, an experimental tool for streamlining cross-platform user interface (UI) development.

January 27, 2025

Sonatype announced its integration with Buy with AWS, a new feature now available through AWS Marketplace.

January 27, 2025

Endor Labs, Aikido Security, Arnica, Amplify, Kodem, Legit, Mobb and Orca Security have launched Opengrep to ensure static code analysis remains truly open, accessible and innovative for everyone:

January 23, 2025

Progress announced the launch of Progress Data Cloud, a managed Data Platform as a Service designed to simplify enterprise data and artificial intelligence (AI) operations in the cloud.

January 23, 2025

Sonar announced the release of its latest Long-Term Active (LTA) version, SonarQube Server 2025 Release 1 (2025.1).

January 23, 2025

Idera announced the launch of Sembi, a multi-brand entity created to unify its premier software quality and security solutions under a single umbrella.

January 22, 2025

Postman announced the Postman AI Agent Builder, a suite empowering developers to quickly design, test, and deploy intelligent agents by combining LLMs, APIs, and workflows into a unified solution.

January 22, 2025

The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the graduation of CubeFS.