Ideally please provide tangible data with figures...

I will update this thread with some findings:

  • OSS-RISK-6 : Untracked Dependencies
    • https://github.com/OWASP/www-project-open-source-software-top-10/blob/main/0-1-risks/OSS6-Untracked-Dependencies.md
  • Identifying Challenges for OSS Vulnerability Scanners - A Study & Test Suite
    • https://www.bodden.de/pubs/dph+21identifying.pdf