ActiveState noted that JFrog and Endor Labs also stress artifact and agent controls.
Public source
Publisher name
Public post
Weekend Software Supply Chain Strategist Brief 📅 September 6, 2026 Executive brief 👉 Autonomous agents are now a supply-chain risk. Manifold’s “GitSpawn” lets maliciou…
Company
ActiveState
Secure your OSS with ActiveState! Get intelligent remediation via our Open Source Security Posture Management platform.
- Industry
- Software Development
- Location
- Vancouver, CA
- Company size
- 51–200 employees
About ActiveState
ActiveState enables DevSecOps teams to improve their security posture while simultaneously increasing productivity and innovation to deliver secure applications faster. The company provides a trusted catalog of more than 79 million secure open source components and container images that can be consumed via AI coding assistants, artifact repository, CI/CD, IDE, or directly from ActiveState. ActiveState continuously monitors and updates the open source components to help keep companies vulnerability free. Companies using ActiveState see a 60-99% reduction in CVEs, improving their security posture, and save as much as 30% of developer time, eliminating the engineering toil typically associated with using open source software in commercial applications.
See moreLatest activity
Latest activity from ActiveState
13 signals
Research & Knowledge
ActiveState CEO Abby Kearns explores the tension between compliance and foundational product knowledge in The Hacker News.
Legal & Regulatory
ActiveState noted that pre-execution enforcement is displacing post-ingestion scanning.
Legal & Regulatory
ActiveState noted that Nvidia agreed to acquire Hugging Face for $12.93 billion and promises openness and neutrality.
Discover more
Similar signals
Similar public activity from other companies.
Legal & Regulatory
Cloudsmith
Cloudsmith notes that the CRA's reporting obligations start on September 11, requiring manufacturers to report actively exploited vulnerabilities to ENISA within 24 hours.
Legal & Regulatory
Chainguard
Chainguard Containers achieved SLSA Build Level 3, verified by independent assessment
Legal & Regulatory
Finite State
Finite State noted that its supplier gave the company that binary isn't a defense under the CRA, but rather the normal condition of embedded development that the regulation is designed around.
Products & Services
Moderne
Moderne sees JFrog building an ecosystem response to unmaintained OSS
Products & Services
Endor Labs