How Much Open Source Is Abandoned? It Depends How You Count
A 13.1 million-package analysis finds that open-source abandonment rates can vary by multiples, exposing a major software supply-chain measurement gap.
A 13.1 million-package analysis finds that open-source abandonment rates can vary by multiples, exposing a major software supply-chain measurement gap.
A cascading series of supply-chain compromises spanning GitHub pipelines, npm, PyPI, and core developer tools has exposed how deeply attackers can exploit the trust fabric of modern software, leaving organizations scrambling to assume everything is compromised.
Industry veteran Theresa Lanowitz says the modern software supply chain has become too complex to see, too critical to ignore, and too exposed to secure the old way.
As AI accelerates development and expands the attack surface, organizations are waking up to a harsh reality: the software supply chain is now their most fragile and least understood security risk.
The Notepad++ incident isn't just another nation-state compromise. This attack highlights how developer tools are a governance blind spot, ongoing weaknesses in the integrity of update mechanisms, and the continued evolution of supply chain attacks.
We picked the top three news events of 2025. It wasn't easy: and neither will be 2026.