ActiveState noted that CrowdStrike now intercepts npm and PyPI downloads before execution using package-age rules, registry restrictions, and secure-version fallbacks.

Public source

Publisher name

Public post

Weekend Software Supply Chain Strategist Brief 📅 September 6, 2026 Executive brief 👉 Autonomous agents are now a supply-chain risk. Manifold’s “GitSpawn” lets maliciou…

Log in to read the full post

Company

About ActiveState

ActiveState enables DevSecOps teams to improve their security posture while simultaneously increasing productivity and innovation to deliver secure applications faster. The company provides a trusted catalog of more than 79 million secure open source components and container images that can be consumed via AI coding assistants, artifact repository, CI/CD, IDE, or directly from ActiveState. ActiveState continuously monitors and updates the open source components to help keep companies vulnerability free. Companies using ActiveState see a 60-99% reduction in CVEs, improving their security posture, and save as much as 30% of developer time, eliminating the engineering toil typically associated with using open source software in commercial applications.

See more

Latest activity

13 signals

Discover more

Similar public activity from other companies.

Customize signals for your business.

Know everything happening across the B2B world, and act on the company movements that matter to you.

© 2026 SeedOpsCompany intelligence.

SeedOps.