<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[2026 Open Source Security and Risk Analysis Report – Software Governance in the AI Era – Black Duck Software, Inc.]]></title><description><![CDATA[<p dir="auto"><a href="https://www.blackduck.com/content/dam/black-duck/en-us/reports/rep-ossra.pdf" rel="nofollow ugc">https://www.blackduck.com/content/dam/black-duck/en-us/reports/rep-ossra.pdf</a></p>
<blockquote>
<p dir="auto">The “Open Source Security and Risk Analysis” (OSSRA) report has been the industry’s definitive look at the state of open source code for a decade. Each year, we analyze anonymized findings from commercial codebases audited by the Black Duck Audit Services team, and this provides an unmatched, real-world view of how open source is used—and sometimes misused—across every major industry. This year’s findings document a pivotal moment: The explosion of AI-assisted development has fundamentally altered the risk landscape for software and the baseline for compliance with new regulatory initiatives such as the EU Cyber Resilience Act (CRA) and the Digital Operational Resilience Act (DORA).</p>
</blockquote>
<p dir="auto">PDF, 44 pages.</p>
<h2>Context</h2>
<p dir="auto"><a href="https://billboard.bsd.cafe/topic/220/open-source-organisations-weigh-in-on-age-attestation">Open source organisations weigh in on age attestation</a></p>
<h3>Availability</h3>
<p dir="auto"><a href="https://www.reddit.com/r/freebsd/comments/1tu5ezw/comment/opgthoe/" rel="nofollow ugc">Noted in Reddit</a>:</p>
<blockquote>
<p dir="auto">… easily found with Google – without completing Black Duck's form, which requires a business email address:</p>
<ul>
<li><a href="https://www.google.com/search?q=%222026+Open+Source+Security+and+Risk+Analysis+Report%22+PDF&amp;udm=14" rel="nofollow ugc">https://www.google.com/search?q="2026+Open+Source+Security+and+Risk+Analysis+Report"+PDF&amp;udm=14</a></li>
</ul>
<p dir="auto">…</p>
</blockquote>
]]></description><link>https://billboard.bsd.cafe/topic/221/2026-open-source-security-and-risk-analysis-report-software-governance-in-the-ai-era-black-duck-software-inc.</link><generator>RSS for Node</generator><lastBuildDate>Wed, 03 Jun 2026 10:35:14 GMT</lastBuildDate><atom:link href="https://billboard.bsd.cafe/topic/221.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 03 Jun 2026 07:08:04 GMT</pubDate><ttl>60</ttl></channel></rss>