
David A. Wheeler at The Linux Foundation outlines what all software developers should know about open source software security
I was recently asked, “what’s the role of grassroots education in developing secure software and securing software supply chains?” My answer is “none, because we lack grass.”
“Grassroots education” implies ordinary practitioners teaching their peers, like grass spreading from its roots across an area once it has grown in one part of the area. Grassroots education can be effective when information is widely but not universally known.
There’s just one problem: we lack grass. Relatively few software developers know how to develop secure software, or how to secure their software supply chains. That’s because we don’t teach developers what they need to know.
A 2019 Forrester report titled “Show, Don’t Tell, Your Developers How to Write Secure Code” found that none of the top 40 US schools or top 5 non-US Computer Science schools required students to learn how to implement secure software (sometimes called “secure coding”).
In 2022, of U.S. News’ top 24 Computer Science schools, only one (University of California San Diego) requires security for undergraduates. Ponemon Institute’s Application Security in the DevOps Environment says 53% of developers’ organizations don’t require any training on securing coding (never mind secure software development more generally).
One study seemingly contradicts this but actually proves the point. The State of Developer-Driven Security Survey by Secure Code Warrior in 2022 said 89% of developers report they’ve received “sufficient training” in secure coding.
That’s misleading. The survey also shows most were unfamiliar with common software vulnerabilities, how to avoid them, and how they can be exploited. Nearly all said they needed more training on security frameworks, and over 80% said they are still knowingly shipping vulnerabilities in code and find it challenging to “practice secure coding” (their term).
This is not “sufficiently trained” at all! Developers have been taught so little that they now have unreasonably low expectations, surrounded by others who know equally little. The relatively rare knowledge of secure software development makes its spread slow.
Worse, knowledgeable developers leave the field, leaving behind less knowledgeable developers, resulting in ineffective peer education.
This is a problem. Our society depends on software – software that hostile actors now repeatedly attack. But since most software developers don’t know how to develop secure software, let alone protect supply chains, the result is an endless series of security problems.
What should software developers learn? Here are examples of what all software developers should know:
Ignorance permeates the entire software industry. It’s not an open source software (OSS) problem, nor is it a closed source software problem. Indeed, many developers develop both.
That said, today’s applications are 70-90% OSS components once you look inside them, so all developers must know how to select and reuse OSS. OSS gives potential evaluators a lot more information, but using that information effectively requires knowing how. And while OSS has a potential security advantage, since anyone can review it, reviews don’t matter if the reviewers also can’t develop secure software.
We should expect software developers to know how to develop secure software, how to select secure reused components, and how to secure their supply chains (both inbound and outbound). Since this can’t happen just through grassroots efforts, we need our educational system – including colleges, universities, and software development bootcamps – to do their part in teaching software developers this as a mandatory part of their education.
The Linux Foundation, specifically its Open Source Security Foundation (OpenSSF), has been taking steps to improve education in developing secure software and securing software supply chains. It has developed some courses in developing secure software, and its Open Source Software Security Mobilization Plan discusses its intended steps to improve education.
Unfortunately, it’s going to take a while for these newer developers to pervade the field, so organizations will also need to get their software developers into courses that teach them how to do this. The OpenSSF’s Secure Software Development Fundamentals Courses are a good place to start, and they cost nothing.
As more and more developers do have the necessary knowledge, they can begin to help their peers who haven’t learned yet. At some point, we’ll finally have enough grass.
David A. Wheeler is Director of Open Source Supply Chain Security, The Linux Foundation
Main image courtesy of iStockPhoto.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543