Knowing an application contains open source components is not the same as understanding the software and communities behind them. For many organizations, the software supply chain extends across thousands of dependencies, developed and maintained by communities, foundations, vendors, and individual contributors. Red Hat Chief Technology Officer Chris Wright described this as the enterprise software fabric : a shared network where developers from different companies, projects, and communities build and maintain code together. That collaboration is one of open source's greatest strengths.
It allows organizations to build on shared innovation, benefit from decades of engineering investment, and contribute improvements back to the communities on which they depend. But as organizations build more of their software on this shared foundation, they also need greater visibility into what they’re depending on, where it comes from, and how it’s sustained. That question is becoming more important as governments and regulators place greater emphasis on software supply-chain security.
Enterprises increasingly need to know whether they understand the open source software in their products and applications well enough to manage risk throughout its lifecycle. With open source, a component may be actively maintained today and unsupported tomorrow. A vulnerability may be disclosed in a dependency that few people inside the organization even knew was present. And when an upstream project can no longer respond, the responsibility for addressing the problem can move downstream. In the European Union, the Cyber Resilience Act (CRA) sets cybersecurity requirements for digital products.
Vulnerability reporting began September 11, 2026, with the main requirements taking effect December 11, 2027. For enterprises that develop or sell products in scope of the CRA, this creates a practical challenge: understanding every component in your commercial software is no longer optional—it’s a legal requirement. The average commercial codebase now contains more than 84,000 files , roughly 4 times the number seen 5 years ago. AI-assisted development adds to that complexity. Coding assistants can generate functions, suggest libraries, reuse implementation patterns, and produce working code in seconds.
