The vast majority of today’s applications are made up of open source components. The 2022 “Open Source Security and Risk Analysis” (OSSRA) report, conducted by the Black Duck Cybersecurity Research Center (CyRC), found that 97% of the 2,400+ codebases analyzed were contained open source.
Understanding what’s in your codebase is essential, and for M&A transactions it’s one of the key drivers for performing software due diligence. Identifying open source risks, security flaws, and code quality issues ensures there are no surprises for acquirers, and earlier detection protects the value of a deal.
Phil Odence, general manager of Black Duck Audits at Black Duck, oversees a team that advises on the software due diligence activities of over 500 M&A transactions every year. He spoke with Transaction Advisors on the importance of software due diligence and the critical information organizations can get from them. He also discusses the impact the pandemic has had on M&A due diligence over the last year. Watch the interview to learn more.