Company intelligence
ActiveState
Secure your OSS with ActiveState! Get intelligent remediation via our Open Source Security Posture Management platform.
About ActiveState
ActiveState enables DevSecOps teams to improve their security posture while simultaneously increasing productivity and innovation to deliver secure applications faster. The company provides a trusted catalog of more than 79 million secure open source components and container images that can be consumed via AI coding assistants, artifact repository, CI/CD, IDE, or directly from ActiveState. ActiveState continuously monitors and updates the open source components to help keep companies vulnerability free. Companies using ActiveState see a 60-99% reduction in CVEs, improving their security posture, and save as much as 30% of developer time, eliminating the engineering toil typically associated with using open source software in commercial applications.
Verified activity
Signals from ActiveState
13 published signals
Research & Knowledge
ActiveState CEO Abby Kearns explores the tension between compliance and foundational product knowledge in The Hacker News.
Reported by ActiveState
Legal & Regulatory
ActiveState noted that pre-execution enforcement is displacing post-ingestion scanning.
Reported by Eric Gallagher
Legal & Regulatory
ActiveState noted that Nvidia agreed to acquire Hugging Face for $12.93 billion and promises openness and neutrality.
Reported by Eric Gallagher
Legal & Regulatory
ActiveState noted that JFrog and Endor Labs also stress artifact and agent controls.
Reported by Eric Gallagher
Legal & Regulatory
ActiveState noted that CrowdStrike now intercepts npm and PyPI downloads before execution using package-age rules, registry restrictions, and secure-version fallbacks.
Reported by Eric Gallagher
Legal & Regulatory
ActiveState noted that Apache scanned 230 repositories in 3 days and routed findings through established channels.
Reported by Eric Gallagher
Legal & Regulatory
ActiveState announced that the CRA becomes operational on September 11, 2026, requiring manufacturers and open-source stewards to report exploited vulnerabilities and severe incidents through ENISA with a 24-hour warning, 72-hour notice, and final report.
Reported by Eric Gallagher
Research & Knowledge
ActiveState published a piece discussing security leaders' questions about vulnerability reporting, KEV, and EPSS.
Reported by Abby Kearns
Research & Knowledge
ActiveState published Episode 2 of the story of what happened and the history of software supply chain security.
Reported by Eric Gallagher
Presence & Recognition
ActiveState released Episode 3 of the Great Moments in Software Supply Chain History series featuring a student and thousands of strangers.
Reported by Eric Gallagher
Presence & Recognition
ActiveState CEO Abby Kearns explores how AI is fundamentally altering the threat landscape in an interview with Security Editor Alex Scroxton at ComputerWeekly.com
Reported by ActiveState
Products & Services
ActiveState's registry goes offline on October 22, 2026.
Reported by Austin Gilmore
Research & Knowledge
ActiveState published a new article breaking down why vulnerabilities that were already known stopped being a defense under the EU Cyber Resilience Act.
Reported by ActiveState