Insights from JFrog’s State of the Union Report

Insights from JFrog's State of the Union Report

The News: JFrog’s annual Software Supply Chain State of the Union report for 2024 reveals that most critical vulnerability scores are misleading, highlighting the need for a deeper understanding of software security risks. Read the full press release here.

Insights from JFrog’s State of the Union Report

Analyst Take: JFrog’s findings highlight the significant implications for developers in the current software development ecosystem. Developers are at the forefront of tackling these issues as security concerns rise in tandem with rapid innovation. The accuracy with which traditional vulnerability score metrics, such CVSS ratings, measure the true risk posed by exploits is falling short. When teams struggle to prioritize security fixes based on faulty severity assessments, the discrepancy frequently results in the misallocation of resources and delays in software development cycles.

Furthermore, JFrog’s analysis reveals an important finding: a sizable percentage of vulnerabilities that have been reported are not exploitable. This emphasizes how crucial it is for engineers to distinguish between theoretical vulnerabilities and those that pose real concerns. Making this distinction is essential to focusing attention on vulnerabilities that actually threaten user data and software integrity.

The increasing frequency of Denial of Service (DoS) attacks in contrast to Remote Code Execution (RCE) vulnerabilities highlights how security risks are changing. RCE vulnerabilities provide attackers with unauthorized access to critical backend systems, possibly jeopardizing sensitive data and system integrity, while DoS attacks have the ability to disrupt services. This change emphasizes how important it is for developers to mitigate RCE vulnerabilities first in order to prevent more severe breaches.

The constant struggle for developers is to strike a balance between security needs and productivity expectations. Development delays are caused in part by the lengthy approval processes for integrating new packages and libraries as well as the significant time required for vulnerability remediation. It is crucial to streamline security practices without compromising productivity, which calls for the development, security, and operations teams to work together to effectively integrate security into the software development lifecycle (SDLC).

Moreover, developers have both opportunities and challenges as a result of the widespread availability of security tools. Although these tools are useful for identifying and mitigating vulnerabilities, their widespread use may result in tool sprawl and higher levels of complexity. If developers want to improve productivity and optimize workflows, they should thoroughly assess and consolidate security solutions. Nonetheless, the industry’s hesitancy to fully adopt emerging technologies is evident in the cautious adoption of AI/ML-powered code generation tools. Developers navigating the changing software development landscape have to continue prioritizing finding a balance between utilizing AI/ML capabilities for increased security and limiting the potential risks associated with automated code production.

Developers are essential to tackling the challenges of enterprise software supply chain security in the face of rapid technological development. Through vigilant monitoring of emerging threats, the implementation of comprehensive security protocols, and the selective adoption of innovative techniques, developers can efficiently manage risks and foster innovation and productivity in software development initiatives.

Looking Ahead

The Software Supply Chain State of the Union report from JFrog provides insightful information about the opportunities and challenges that developers face in the fast-paced world of modern software development. Organizations need to take a sophisticated approach to risk assessment and mitigation as long as vulnerabilities prevail and security concerns persist. Developers should prioritize security measures while preserving innovation and productivity in their software development processes by utilizing the insights offered by the research.

Looking ahead, collaboration between the development and security teams will be critical to protecting software supply chains from new and emerging threats. Furthermore, implementing integrated security solutions and using AI/ML-powered technologies appropriately will be essential for improving resilience and reducing risks. Developers should expect an ongoing emphasis on comprehensive security protocols and the integration of innovative technologies in order to tackle the obstacles presented by emerging threats.

Developers can navigate these issues and ensure the integrity and security of their software assets in an increasingly interconnected world by being proactive and adaptable in the face of changing security landscapes.

Disclosure: The Futurum Group is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of The Futurum Group as a whole.

Other Insights from The Futurum Group:

Microsoft Announces New Demand Planning and Copilot Capabilities for Dynamics 365 Supply Chain Management – Futurum Tech Webcast – Interview Series

Ateliere Launches Media Supply Chain Analysis and Consulting Programs

o9 Solutions and AWS Advancing Collaboration for Efficiency

Author Information

With over 25 years of experience, Paul has a proven track record in implementing effective go-to-market strategies, including the identification of new market channels, the growth and cultivation of partner ecosystems, and the successful execution of strategic plans resulting in positive business outcomes for his clients.

Sam holds a Bachelor of Science degree in Management Information Systems and Business Analytics from Colorado State University and is passionate about leveraging her diverse skill set to drive growth and empower clients to succeed in today's rapidly evolving landscape.

Related Insights
Synopsys Q3 FY 2026 AI Design Demand Drives EDA Growth
August 31, 2026

Synopsys Q3 FY 2026: AI Design Demand Drives EDA Growth

Futurum Research analyzes Synopsys’ Q3 FY 2026 earnings, focusing on AI-driven EDA demand, Ansys integration, and FY 2027 monetization priorities....
NVIDIA Q2 FY 2027 AI Infrastructure Demand Extends Into FY 2028
August 31, 2026

NVIDIA Q2 FY 2027: AI Infrastructure Demand Extends Into FY 2028

Futurum Research analyzes NVIDIA’s Q2 FY 2027 earnings, focusing on AI infrastructure demand, Vera Rubin production, Blackwell Ultra momentum, and FY 2028 growth expectations....
OPSWAT Closes File-Inspection Gaps With MetaDefender Core v5.22.0
August 31, 2026

OPSWAT Closes File-Inspection Gaps With MetaDefender Core v5.22.0

OPSWAT's MetaDefender Core v5.22.0 introduces a File Structure Validation Engine and FIPS 140-3 compliant database, positioning the platform for government and regulated-sector growth as the SLE market expands....
Damovo's SovereignStack: Ending Public-Sector Comms Fragmentation
August 31, 2026

Damovo’s SovereignStack: Ending Public-Sector Comms Fragmentation

Damovo introduces SovereignStack, the first integrated sovereign communications platform for the German public sector, unifying Rocket.Chat, Pexip, and Mitel to eliminate fragmentation and streamline government operations....
Tieto's €5M Buyback: Confidence Signal in a Growing SLE Market
August 30, 2026

Tieto’s €5M Buyback: Confidence Signal in a Growing SLE Market

Tieto Corporation's €5M share repurchase signals management confidence as the Software Lifecycle Engineering market surges 15.4% annually through 2028, reflecting strong enterprise demand fundamentals....
vLLM Becomes Production Infrastructure at PyTorch Conference 2026
August 29, 2026

vLLM Becomes Production Infrastructure at PyTorch Conference 2026

vLLM crosses from research project to multi-vendor production infrastructure at PyTorch Conference North America 2026, with sessions on KV cache management, disaggregated serving, and hardware portability across 20+ accelerator architectures....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.