This report begins with an overview of the state of software security, examining the prevalence and trends of security flaws in applications. It then delves into the frequency and criticality of these flaws, as well as their common types and origins. The report also explores the speed of flaw remediation and the concept of software security debt, including factors contributing to it and recommendations for minimizing it. Additionally, it discusses securing the software supply chain, focusing on open-source dependencies, assessing third-party libraries' security, and addressing security debt within the supply chain. Download Veracode’s latest SOSS to learn more.