The overwhelming majority of security weak points in open source projects are located in secondary components rather than primary ones.
“Aggregating the numbers from all ecosystems, we found more than three times as many vulnerabilities in secondary components as we did in primary ones”, said Alyssa Mille who works at Snyk, in her interview, discussing the company's security posture.
The report examined how the vulnerabilities affected the JavaScript (npm), Ruby (RubyGems), Java (MavenCentral), PHP (Packagist) and Python (PyPI) ecosystems.
Snyk reported that 86% of JavaScript security bugs, 81% of Ruby bugs, and 74% of Java bugs affected libraries that depended on the main components loaded within a project.
Snyk argues that companies that scan their core components for security issues without investigating other components will end up running products that are vulnerable to unforeseen errors.
But while security bugs were prevalent in JavaScript, Ruby, and Java, they were not in PHP and Python, where the vast majority of bugs were in direct dependencies (primary components). However, there is a reason for this.
“I sincerely believe that it is more about the developmental approach of the ecosystems themselves”, Miller said to ZDNet.
“The Java and Node.js projects, in particular, appear to use dependencies “much heavier” than other ecosystems. Specifically, when you examine the massive size of the Node.js ecosystem, packages that create or leverage core functions from other packages are almost the rule.”.
“This ‘foreign risk,’ as we like to call it, is at the heart of some high-profile breaches and a root cause of complexity in software supply chain security,” Miller said.

Some bugs had a large impact
But Snyk's team didn't just look at the place of these bugs in the open source ecosystem, but also what kind of bugs they were.
Another interesting finding is that most of the new security flaws discovered in 2019 were cross-site scripting (XSS) bugs, but despite their large number, these only affected a small portion of real-world projects.
Instead, two dozen “prototype pollution” bugs had the biggest impact of all the bugs discovered last year, affecting more than 115,000 different open source, and probably even more private ones.
Of these, the "prototype pollution" bugs in jQuery and LoDash had the biggest impact, as these frameworks are some of the most widely used tools today.
However, the Snyk team noted something else in its report – that the «malicious packages» were ranked as the second most common type of security issue they found in projects last year.
According to Snyk, last year, compromised or malicious packages were the second most common source of security issues for open source.
“The overwhelming majority, over 87%, came from npm packages [JavaScript]”, Miller said to ZDNet.
