code bases have OSS vulnerabilities 2 % of organizations worldwide will have experienced attacks on their software supply chains by 2025 3 81 45 742 Increasingly, the software development lifecycle (SDLC) itself has become a vector for attacks. The recent Log4J, SolarWinds, Kaseya, and Codecov hacks highlight vulnerable surface areas exposed in the SDLC. 1. Sonatype, 2023 - State of the Software Supply Chain 2. Synopsys, 2022 - Open Source Security and Risk Analysis Report 3. Gartner, 2021 - How Software Engineering Leaders Can Mitigate Software Supply Chain Security Risks 4. IDC, 2022 - IDC FutureScape: Worldwide Developer and DevOps 2022 Predictions % in response to the above, by 2024, 55% of organizations will demand DevOps pipeline security to secure the software supply chain to lower the risk of compromise 4 55 Supply chain attacks are increasingly successful