# linskens-sonatype-securite-vitesse-ia-quatre-ans-2026-08-18

## Veille

Blog post from **Sonatype** by **Aaron Linskens** (*technical writer*), published on **August 18, 2026**, ~1,300 words: it recounts a **Sonatype Research Labs** study spanning **49 months** (June 2022 — June 2026) and a **fixed cohort** of enterprise applications, a methodological choice asserted to isolate the evolution of the application fleet rather than that of the customer portfolio. The result is presented as a contradiction: remediation is faster, yet risk accumulates further. (A) **The stock is rising** — *Critical* and *High* vulnerabilities per application **×4.31** (from **14.14** in June 2022 to **54.3** in 2026, still **×3.91** excluding legacy applications newly brought under management), newly affected component versions at **46×** the pre-AI rate, monthly application creation **×4.84**. (B) **Remediation is improving** — more than half of resolved violations are resolved in under a day, the median age of unresolved *Critical/High* vulnerabilities drops from **228** to **126 days**, then to **103** in May 2026; among cohorts that had twelve months, **52.6%** are resolved, **44.3%** open, **3.1%** under waiver. (C) **The proposed lever is component selection**: at the moment a vulnerable dependency was chosen, a substantially less risky version already existed in **62.2%** of cases on **Maven**, **46.9%** on **npm**, **34.3%** on **PyPI** — a gap the text attributes to an information gap rather than developer fault. The post itself states that AI is not the sole cause of the acceleration, and concludes on **Sonatype Guide**, which brings this intelligence to the point of selection. On the supply-chain side, it extends what [[fiches/2026-08/staples-gitlab-when-code-is-abundant-2026-08-24]] frames in economic terms and [[fiches/2026-07/clinton-anthropic-secure-ai-native-sdlc-2026-07-21]] in secure-cycle terms.

## Titre Article

Securing Software at the Speed of AI: What Four Years of Data Reveal

## Date

2026-08-18

## URL

https://www.sonatype.com/blog/securing-software-at-the-speed-of-ai-what-four-years-of-data-reveal

## Keywords

software supply chain, software supply chain, Sonatype Research Labs, fixed cohort, longitudinal study, Critical and High vulnerabilities, vulnerability advisory, affected component versions, open source dependencies, component selection, less risky version, median vulnerability age, remediation time, waiver, Maven, npm, PyPI, prevention vs remediation, AI coding assistant, component intelligence, organizational policy, Sonatype Guide, The AI-Era Software Assembly Line, AI era

## Authors

Aaron Linskens, *technical writer* chez Sonatype, sur le blog de l'éditeur ; les chiffres sont produits par Sonatype Research Labs, non par l'auteur.

## Ton

Profile: vendor blog post recounting a study — short format, five subheadings, a list of figures per section, measured and unemphatic tone, targeting application security leads, platform teams, and tooling-purchase decision-makers. The register is that of a **data-backed report**: every claim is anchored to a measurement, percentages are given with their base (number of months, comparison periods, ecosystems named separately), and the method is laid out before the results. Two gestures of caution are explicit in the text, which is uncommon for this format: the plurality of causes is acknowledged (*« AI alone did not cause this acceleration »*, with four alternative factors named, including the improvement of vulnerability research itself), and the measured gap in version choice is expressly removed from the register of fault (*« This should not be interpreted as developer failure »*). The rhetoric rests on an **apparent contradiction** posed upfront and sustained throughout: faster remediation, higher accumulated risk, hence the proposed shift of focus upstream. The commercial intent is owned in the final section, which names the product and ties it to the figure that motivates it. Authority rests on the vendor's observatory position — a vulnerability-advisory catalog, an instrumented application fleet — and the post points to the full report, *The AI-Era Software Assembly Line*, for the underlying data.

## Pense-betes

- **The contradiction is the main result**, and it is arithmetic before it is strategic: remediation is accelerating (median age **228 → 126 → 103 days**) while the stock per application quadruples (**14.14 → 54.3** *Critical/High*). Remediating faster is not enough when the inbound flow grows faster than processing capacity.
- **An application's risk moves even when its code doesn't.** Direct formulation from the post: a dependency deemed acceptable yesterday can receive a disclosure tomorrow, become unmaintained, or see a safer version released. Consequence for internal monitoring: a frozen inventory is not a security state, and the absence of a commit is not the absence of an event.
- **The most actionable figure is that of the available version**: at the time of selection, a substantially less risky version already existed in **62.2%** of cases on **Maven**, **46.9%** on **npm**, **34.3%** on **PyPI**. The gap between ecosystems is itself a data point — it ranks where prevention pays off most.
- **Two distinct causes behind the same symptom**: some vulnerabilities are unavoidable (the ecosystem offers no safer option), others are **information problems** (the one choosing — human or assistant — lacks the right context at the moment of choice). Only the second class is addressable through tooling at the point of selection.
- **The tension point specific to AI**, as the post frames it: an assistant can recommend and introduce a component in seconds, but *« a fast recommendation is not necessarily an informed one »* — it needs **current** intelligence on risk, available versions, maintenance, and internal policy, which knowledge frozen in the model's weights does not guarantee.
- **What the post does not quantify**, and should be requested from the full report before citing: the **cohort size** (no application count given), the **value of the January 2024 peak** — the **59%** decline refers to it, while the **45%** decline starts from 228 days, hence two different baselines —, and the **start date of "the AI era"**, used as a comparison boundary without being defined.
- **Causal honesty is carried by the text itself**: four alternative factors to AI are named for the expansion of the vulnerability landscape — better research, better disclosure, AI-assisted security research, and evolving attacker behavior. The position taken is pragmatic: *« Organizations don't need to prove a single cause to confront the outcome. The scale itself is the problem. »*
- **Related**: [[fiches/2026-08/claxton-anthropic-ai-native-sdlc-playbook-2026-08-21]] (the skill advises, the hook constrains — here, component policy is exactly what stands to gain from becoming deterministic at the moment of choice) and [[fiches/2026-07/sfeir-code-review-anneau-contraintes-2026-07-30]] (the ring of constraints around the agent, of which dependency selection is a rarely instrumented upstream link).

## RésuméDe400mots

Sonatype publishes, written by its *technical writer* Aaron Linskens, a synthesis of a longitudinal study by its research labs spanning forty-nine months, from June 2022 to June 2026. The method is stated upfront: a fixed cohort of applications tracked continuously, so that the measured variations reflect the evolution of the software fleet rather than that of the customer portfolio. The central result is presented as a contradiction: organizations remediate faster than before, yet their applications accumulate more risk.

Four measures frame the finding. *Critical* and *High* vulnerabilities per application were multiplied by 4.31, rising from an average of 14.14 in June 2022 to 54.3 in 2026; the effect is not driven by legacy alone, since excluding legacy applications recently brought under management still leaves a factor of 3.91. Newly affected component versions are advancing at forty-six times the pre-AI rate. The median age of vulnerabilities has fallen 59% since its peak in January 2024. Finally, the average monthly creation of applications was multiplied by 4.84, and with it the dependency decisions.

The progress in remediation is real: more than half of resolved violations are resolved in under a day, and the median age of unresolved *Critical/High* vulnerabilities drops from 228 to 126 days, then to 103 days in May 2026. Among cohorts with at least twelve months to act, 52.6% are resolved, 44.3% remain open, and 3.1% are under waiver.

The proposed shift concerns the upstream. The researchers examined the vulnerable dependencies that entered the period's applications and asked a simple question: at the time of selection, did a substantially less risky version already exist? The answer is yes in 62.2% of cases on Maven, 46.9% on npm, and 34.3% on PyPI. The text declines to read this as developer fault: some vulnerabilities are unavoidable, others stem from an information gap at the time of the choice — a point that becomes sensitive when an AI assistant can introduce a component in seconds without having up-to-date intelligence on its risk and on organizational policy.

The post acknowledges that AI is not the sole cause of the expanding vulnerability landscape and cites four competing factors. It concludes on Sonatype Guide, which brings this intelligence to the point of selection, and points to the full report, *The AI-Era Software Assembly Line*, for the underlying data.

## GrapheDeConnaissance

- Sonatype —publie→ Securing Software at the Speed of AI (DOCUMENT, 0.97)
- Aaron Linskens —a_créé→ Securing Software at the Speed of AI (DOCUMENT, 0.94)
- Sonatype Research Labs —fait_partie_de→ Sonatype (ORGANISATION, 0.92)
- Sonatype Research Labs —mesure→ vulnérabilités Critical/High par application ×4,31 entre juin 2022 et juin 2026 (MESURE, 0.94)
- Sonatype Research Labs —mesure→ 14,14 vulnérabilités Critical/High par application en juin 2022, 54,3 en 2026 (MESURE, 0.93)
- Sonatype Research Labs —mesure→ versions de composants nouvellement affectées à 46× le rythme d'avant l'IA (MESURE, 0.9)
- Sonatype Research Labs —mesure→ âge médian des Critical/High non résolues de 228 à 126 jours, puis 103 jours en mai 2026 (MESURE, 0.93)
- Sonatype Research Labs —mesure→ création mensuelle moyenne d'applications d'entreprise ×4,84 (MESURE, 0.9)
- Sonatype Research Labs —mesure→ une version moins risquée était déjà disponible dans 62,2 % des cas sur Maven, 46,9 % sur npm, 34,3 % sur PyPI (MESURE, 0.93)
- cohorte fixe d'applications —permet→ isoler l'évolution du parc plutôt que celle du portefeuille clients (CONCEPT, 0.9)
- Securing Software at the Speed of AI —affirme_que→ la remédiation s'accélère alors que le risque accumulé par application augmente (AFFIRMATION, 0.94)
- Securing Software at the Speed of AI —affirme_que→ le profil de sécurité d'une application change sans que son code change (AFFIRMATION, 0.92)
- Aaron Linskens —affirme_que→ l'IA n'est pas la cause unique de l'expansion du paysage de vulnérabilités (AFFIRMATION, 0.92)
- Aaron Linskens —affirme_que→ l'écart de version relève d'un défaut d'information, pas d'une faute de développeur (AFFIRMATION, 0.9)
- sélection de composant —réduit→ travail de remédiation en aval (CONCEPT, 0.89)
- Aaron Linskens —recommande→ déplacer la question du délai de correction vers le choix de la dépendance (AFFIRMATION, 0.9)
- Sonatype Guide —s_applique_à→ point de sélection du composant, y compris dans les flux assistés par IA (CONCEPT, 0.91)
- assistants de codage IA —utilise→ intelligence courante sur le risque et la politique, non figée dans le modèle (CONCEPT, 0.88)
- The AI-Era Software Assembly Line —est_basé_sur→ cohorte fixe d'applications (METHODOLOGIE, 0.89)

---
Canonical: https://www.thekb.eu/en/fiches/linskens-sonatype-securite-vitesse-ia-quatre-ans-2026-08-18/
