As banks and financial services firms automate ever more of their software testing and release pipelines, dependency scanning tools have become a core line of defence against risk.
From identifying vulnerable open source libraries to enforcing security policies inside CI/CD pipelines, automated analysis now underpins how financial institutions assess software quality at scale.
But new data from Sonatype’s 2026 State of the Software Supply Chain report suggests a growing blind spot: automated testing and scanning tools are only as reliable as the data and models that sit behind them.
As artificial intelligence becomes more deeply embedded in developer tooling, quality assurance teams are being forced to rethink their role, shifting from validating application behaviour to validating the signals produced by automated tools themselves.
The implications are particularly acute in financial services, where regulatory expectations around operational resilience, transparency and third-party risk are tightening, and where software supply chains increasingly resemble critical infrastructure.
“The open source bargain holds true: we all move faster because we share.”
– Brian Fox
According to Sonatype’s latest research, open source software usage continues to grow at extraordinary scale, with nearly 10 trillion component downloads recorded in 2025.
That growth has been matched by a sharp rise in software supply chain attacks, with malicious packages designed to execute inside developer environments and CI pipelines rather than targeting end users directly.
“The open source bargain holds true: we all move faster because we share,” commented Brian Fox, co-founder and CTO of Sonatype.
“What’s changed is the scale and the stakes. The commons is production infrastructure now, attackers know it, and AI puts the whole system on fast-forward,” he stressed.
For QA teams inside banks, this reframing matters. Open source components are no longer peripheral dependencies; they are foundational building blocks whose failure or compromise can cascade across systems, services and customers.
“Trust needs to align with the machine-level speed of software,” Fox continued. “That takes intelligence you can enforce in the workflow, not another report to read after an incident.”
AI testing signals
One of the report’s most striking findings relates to the growing use of generative AI to recommend software upgrades and dependency changes.
Fox and his team found that when large language models operated without live vulnerability intelligence, nearly 28 per cent of AI-generated upgrade recommendations referenced component versions that did not exist or suggested known malicious packages.
“When AI selects open source software components for enterprise applications, GPT hallucinated 27.8 per cent of component versions and suggested actual malware packages when operating without real-time intelligence,” the report stated.
For QA and testing teams, this exposes a critical distinction. Automation can accelerate detection, but it cannot replace judgement.
An automated recommendation, whether generated by a scanner or an AI model, becomes another artefact that must itself be tested, validated and contextualised.
“Trust needs to align with the machine-level speed of software.”
– Brian Fox
Beyond AI hallucinations, the report highlights persistent quality issues in vulnerability intelligence itself. Sonatype identified large volumes of false positives, components incorrectly flagged as vulnerable, alongside false negatives where exploitable software went undetected.
The result is growing “noise” inside security and QA workflows, diverting time away from genuine risk reduction. In regulated environments, that noise can also complicate audits, regulatory reporting and internal risk assessments.
For banks operating under frameworks such as the EU’s Digital Operational Resilience Act (DORA), this creates tension. Automated scanning is increasingly expected, but so is demonstrable control over how risks are identified, prioritised and mitigated.

“Testing should include a wide variety of tools and actions, ranging from open source analyses and source code reviews to more advanced testing,” Sonatype executive Ilkka Turunen previously said when discussing how financial institutions are responding to growing reliance on open source software.
The challenge for QA teams is ensuring those tools produce outputs that are trustworthy enough to support regulatory confidence, not just technical efficiency.
As dependency scanning becomes ubiquitous, QA teams are finding themselves responsible for a new layer of assurance: validating the quality of automated signals.
That includes understanding how vulnerability data is curated, how AI models are trained, and where blind spots or delays may exist.
The Sonatype report frames software transparency as a growing global expectation, driven by regulation, customer trust and systemic risk concerns.
For financial services firms, transparency increasingly means being able to explain not just what software is running, but why it was approved and how risks were assessed.
That shift places QA at the centre of organisational resilience. Rather than acting as a final gate before release, testing teams are becoming interpreters of complex automated ecosystems, translating scan results, AI recommendations and policy outcomes into defensible risk decisions.
COMING IN 2026


Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Inside Rabobank: Engineering resilience by design
- Can AI agents finally automate data testing?
- Continuous testing drives DORA compliance
- Why software testing may face a major rethink
- Buy or build? AI rewrites software testing for banks
WATCH NOW

QA FINANCIAL PODCASTS



