Skip to main content

 This post originally appeared in ActiveState News 

https://www.activestate.com/resources/press-releases/activestate-unifies-79m-components-to-launch-worlds-largest-secure-open-source-catalog/





ActiveState Unifies 79M Components to Launch World’s Largest Secure Open Source Catalog

By consolidating 12+ language ecosystems into a single repository, the ActiveState Catalog enables DevSecOps teams to slash CVE exposure by up to 99% and reclaim 30% of engineering time


Vancouver, BC - Feb. 17, 2025 - ActiveState, a global leader in open source language solutions and secure software supply chain management, today announced it has grown its catalog of secure open source components to 79 million, effectively doubling coverage from 2025 and expanding to more than 12 languages. This provides DevSecOps teams one stop for acquiring trusted open source components for their software development and CVE remediation efforts. ActiveState’s catalog now covers the most popular languages used in enterprise software development, including Java, Javascript, Go, Python, and R, among others, and offers the widest breadth and depth of any open source catalog in the market today. This release moves beyond scanners and image‑only hardening to a governed, multi‑language catalog that standardizes how enterprises consume open source. Companies who want to learn more can visit activestate.com

Open Source Offers Opportunities - and Risks

Open source software powers 96% of modern software applications, with most companies using 5 to 7 different open source languages in their development process. While beneficial for speeding software development, open source creates chaos and complexity within DevSecOps teams: Without a unified, secure source for open source, software development teams open their companies up to risk each time they download a new package from the open internet or grab a container image from a public repository. Maintainer integrity is unknown, update schedules are inconsistent, and bad actors exploit known vulnerabilities into zero-day threats. Not only does this threaten companies’ security posture, it creates an endless body of work for developers to manage, maintain, and troubleshoot third-party code to keep it vulnerability-free: they are forced to track CVEs for the components, dependencies, shared libraries, and then update, migrate, and replace components to maintain safety and compliance. This drains as much as 30-50% of valuable time and resources from developers that could be otherwise spent on revenue-driving innovation. Furthermore, it jeopardizes companies’ ability to meet compliance requirements, which can also cause a financial impact. The adoption of AI code generators only increases the volume and opacity of these risks.  

A New “Golden” Path Forward: the ActiveState Catalog

ActiveState’s enterprise-grade, secure catalog enables companies to tame the complexity of open source in their DevSecOps operations. Unlike point solutions focused on a single language or container layer, the ActiveState Catalog is the only solution that unifies component-level coverage across the 12 most-used open source ecosystems - from source code through language libraries and images - into one catalog, standardizing how developers acquire and update open source across languages through a governed golden path. Container images are just one output of the catalog, not the control point itself, which ensures consistency across all entities that leverage open source within an organization. And unlike other solutions, ActiveState doesn’t lock you into a proprietary format that leads to vendor lock-in.  


All components are continuously monitored and maintained by ActiveState, with an industry-leading 5 business day remediation SLA for critical CVEs, and built from source in a SLSA-3 hardened build environment. In 2025, ActiveState’s OSS build factory completed nearly 1 million successful open source builds for more than 200 global clients. These builds incorporate not only the base component, but also the associated language cores, dependencies, and operating systems required by the customer, ensuring complete, secure open source across the stack.  


Organizations choosing the ActiveState Catalog, such as Altair, Cisco, Moody’s, and Tesco, eliminate hours of developers hunting for and evaluating open source from multiple vendors, saving as much as 30% of their time, and improve their company’s overall security posture by reducing CVEs by up to 99%.   


“We use Python, and R in our software development efforts at Statistics Finland, and sourcing, managing, and maintaining those from different sources increased our operational burden and risk profile,” said Juhani Kauppo, project manager, from Statistics Finland. “Partnering with ActiveState and sourcing our OSS from their library has allowed us to strip away that overhead and strengthen our security posture. That gives our developers more time to focus on innovation and brings peace of mind to our security team.”

Delivering the World’s Most Comprehensive Open Source Catalog

The ActiveState catalog grew to 40 million components in mid 2025 when it introduced coverage for Java and  R in addition to Python, Perl, Ruby, and Tcl. As of January 2026, the company has expanded its open source coverage to include other popular languages, including: 

  • Javascript

  • Go 

  • Rust

  • PHP

  • .Net 

  • C, C+, C++

  • C#


This brings the catalog component count to 79 million and growing. 


“Our customers are seeing the benefit of offloading the management and maintenance of open source to ActiveState,” said Bob Shaker, CPTO, ActiveState. “Our built-from-source components, ongoing CVE management, and integration with package repositories gives companies all of the benefits of open source without the headaches or being trapped into only using containers;  ActiveState can also deliver these in native file type or managed distributions. This truly revolutionizes how modern software is managed.”


To learn more about ActiveState’s catalog of secure, trusted open source software, please visit www.activestate.com or Contact Us.   

Comments

Popular posts from this blog

Open Source Compliance Now Has a Deadline. Accountability Now Has a Name.

Open Source Compliance Now Has a Deadline. Accountability Now Has a Name. The US federal safety net that followed Log4j has thinned in the same window the EU Cyber Resilience Act wrote obligations for commercial users of open source software into law, with reporting requirements beginning September 2026. The accountability for what enters your products is moving toward the organizations that consume it, on someone else's timeline. Two things happened to open source software security in the same window, and together they change who is on the hook. The US federal effort that grew after the 2021 Log4j crisis has largely lapsed, with key personnel gone and the initiatives quiet. At the same time, the EU Cyber Resilience Act turned obligations for commercial users of open source software into law, with vulnerability and incident reporting requirements applying from September 2026. One backstop thinned. The other became a requirement with a date attached to it. If the plan was to wai...

The SBOM Just Became a Liability With a Date on It

The SBOM Just Became a Liability With a Date on It When a best practice becomes a product requirement, it stops being a security artifact and starts being a financial one. The question now is whether the document you are obligated to produce is true. The EU Cyber Resilience Act is moving the software bill of materials from a best practice to a product security requirement, with the law’s full application arriving in December 2027 . If your company ships software into the EU, the character of one of your obligations just changed. The software bill of materials you used to produce because it was responsible is becoming one you are legally required to produce because a regulator says so. That is not a procedural change. It moves the bill of materials off the security team’s task list and onto the company’s books, and most organizations have not adjusted to what that means. A best practice and a requirement are not the same liability Every CFO understands that an unmanaged liability is a ...

Discovery Is Outrunning Remediation Everywhere. That Is Not Just a Technology Problem.

Discovery Is Outrunning Remediation Everywhere. That Is Not Just a Technology Problem. A model found 1,596 unpatched vulnerabilities in open source projects last month. The industry’s answer was more infrastructure for finding problems. That was never the part that was broken. Anthropic, Google, OpenAI, Microsoft, and more than a dozen other organizations just did something companies rarely do voluntarily. They pooled money into a shared body, called Akrites and hosted by the Linux Foundation, because none of them could keep pace with open source vulnerability discovery and remediation on their own. Organizations build shared infrastructure at this speed for one reason. A risk got too expensive for any single balance sheet to absorb quietly. That is what a captive insurance pool is. A group of companies decides a risk is real and common enough that carrying it alone costs more than carrying it together. Nobody calls that admission a taskforce. They call it underwriting, and they usual...