Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Open-source software is established infrastructure for many organizations, but the 2025 World of Open Source Survey finds that formal strategy and operational readiness have not kept pace with its adoption. The report describes 40–55% penetration across operating systems, cloud platforms, databases, DevOps, and AI; that is an adoption framing across selected technology areas, not the share of all software that is open source.

How widely organizations use open-source software

The Linux Foundation Research survey, produced with Canonical and authored by Marco Gerosa and Adrienn Lawson, presents open source as a substantial part of organizational technology stacks. Its 40–55% penetration framing covers operating systems, cloud platforms, databases, DevOps, and AI. The figure summarizes reported adoption across those areas; it should not be read as a census of all software or all organizations.

Adoption is not uniform across technology categories. Open-source AI/ML use rose 5 percentage points from 2024 in the survey, a statistically significant change (p = 0.0388) based on the survey samples. That finding describes the reported change in this survey, not a guarantee that adoption will continue at the same pace.

Cybersecurity illustrates the difference between current use and perceived opportunity: 33% of respondents said their organization currently used open source in cybersecurity, while cybersecurity ranked third among areas respondents thought would benefit most from open-source development. This contrast does not establish that open-source security tools are inherently better or worse.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Adoption is ahead of formal organizational readiness

The survey’s central tension is that organizations rely on open source while relatively few report formal structures for managing that reliance. In 2025, 34% said they had a clear open-source strategy and 26% reported an implemented open-source program office (OSPO). The report says those figures increased by 2 and 1 percentage points, respectively, from 2024.

The Linux Foundation reproduces the report’s conclusion: “The 2025 World of Open Source Survey reveals a paradox: while open source software has achieved mission-critical status with widespread adoption across enterprise technology stacks, organizational maturity significantly lags behind this adoption.” The sentence is the report’s conclusion, not a quote attributed to an individual speaker.

What an OSPO can do

An OSPO can provide a home for open-source policy and coordination, including risk management, AI oversight, and software supply-chain security. The 2025 OSPO research page also reports that organizations with OSPOs report higher contribution and other benefits. Those associations do not prove that creating an OSPO alone causes the outcomes; leadership support, a clear strategy, and a credible account of return on investment remain important challenges.

What production use requires from support and maintenance

Using a component at no license cost does not itself provide a production support commitment. For production open-source software, 71% of survey respondents expected a support-provider response in under 12 hours, 53% expected long-term support guarantees, and 47% required rapid security patching. These are expectations reported by respondents, not service levels guaranteed by any provider.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Organizations evaluating a production dependency should decide who owns support and maintenance before an incident occurs. In particular, establish:

  • Who responds to technical issues, and what response time applies to the relevant severity and deployment.
  • Whether a long-term support period is defined, including which versions receive maintenance.
  • How security issues are reported, assessed, and patched, and who is responsible for applying updates.
  • What happens if a project or provider stops maintaining the component.

These decisions are specific to an organization’s deployment and risk tolerance. Community availability can be valuable, but it is not interchangeable with a contractual support arrangement.

How organizations assess a new open-source component

Asked what they usually do before using a new OSS component, respondents reported a mix of project-health, popularity, dependency, and security checks:

Reported check Share of respondents
Check community activity 44%
Check release frequency 37%
Check direct dependencies 36%
Check ratings and download statistics 36%
Run automated security testing 31%
Manually inspect source code 28%

These figures describe self-reported practices, not the effectiveness of those checks or the safety of any particular component. Due diligence works best as a layered review: activity and release cadence can help reveal maintenance patterns; dependency review can expose indirect exposure; automated testing and source inspection can find some issues. None of these checks alone proves that a component is secure, suitable, or sustainable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why organizations hesitate to use or contribute

The survey distinguishes concerns about adopting software from barriers to contributing back. Licensing and intellectual-property questions matter in both, but the reported obstacles are not limited to security vulnerabilities.

Decision Leading reported concerns
Using OSS Licensing/IP concerns (37%); lack of technical support (36%); security concerns (33%)
Contributing to OSS Fear of IP leakage (33%); legal or licensing concerns (33%); uncertain return on investment (29%)

These are survey responses, not proof that each concern applies to every project. Organizations can address them through clear policies for code review and licensing, defined support ownership, and an explicit process for approving external contributions. A contribution policy should make it clear what employees may share, who reviews it, and how legal or business-sensitive material is handled.

Open-source activity is supported by ecosystem institutions

OpenSSF’s 2025 annual report describes activity within that organization: more than 270 active contributors across 112 organizations, nearly 20,000 course enrollments, and $663,000 in Technical Initiative funding awarded by its Technical Advisory Council. These figures indicate the scope of OpenSSF’s reported work; they are not measures of the entire open-source ecosystem.

Lifecycle planning also matters. An Open Source Initiative summary of the Perforce OpenLogic 2025 State of Open Source Report says that 26% of organizations still used end-of-life CentOS, including 40% of large enterprises; one in four of those large organizations had not decided on a migration plan. This is a secondary summary, so it should be treated as a specific warning about reported CentOS use rather than generalized to every distribution or organization.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the 2025 findings mean for organizations

The survey portrays open source as both widely used and unevenly governed. For a team deciding how to manage that dependence, the practical response is to align controls with the role each component plays: review project and dependency health before adoption, assign support and patch responsibilities for production systems, and make licensing and contribution rules understandable to staff. An OSPO may help coordinate those activities where the scale and risk justify it, but governance requires organizational ownership rather than a title or office alone.

All survey percentages reflect respondents’ answers and the report’s stated samples and question wording. They should be understood as survey findings, not universal measures of every organization’s software estate or practices.

Sources: Linux Foundation Research, World of Open Source 2025; Linux Foundation article reproducing the report conclusion; 2025 OSPO research; OpenSSF annual reports; Open Source Initiative summary of the Perforce OpenLogic report.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.