We talk a lot about the code your team writes, but what about the code they borrow?
One of the stickiest findings in the 2026 State of Software Security (SoSS) report revolves around the software supply chain. The data shows that third-party components are a primary source of critical, long-lived security debt.
Figure 8 visualizes this risk. While third-party code only contributes to 9% of all security debt, it’s responsible for 66% of CRITICAL security debt.