ActiveState
banner
activestate.bsky.social
ActiveState
@activestate.bsky.social
ASPM for Taming Open Source Complexity and securing your software supply chain.
That’s a wrap on Black Hat USA 2026! 🎩 ✨

We connected with so many teams already rolling up their sleeves to secure their open-source pipelines. Does your team have an answer to who's vetting your AI code yet?

We do. Let’s talk. 🔒 💙

#BlackHatUSA2026 #Cybersecurity
August 12, 2026 at 8:17 PM
Gartner published its Magic Quadrant for Software Supply Chain Security.

🔹ActiveState has been named a Niche Player.🔹

We govern open source at the point of ingestion: built from source, SLSA Level 3, contractual remediation SLAs.

Read the release: buff.ly/6eB2Ea8
ActiveState Positioned as a Niche Player in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security | ActiveState
ActiveState is named a Niche Player in the 2026 Gartner Magic Quadrant for Software Supply Chain Security, for governing open source at the point of ingestion.
buff.ly
July 7, 2026 at 5:05 PM
ActiveState has sponsored the latest IDC Analyst Brief on open source software governance at scale. What the IDC Analyst Brief found: curated open source catalogs are the only governance model that intervenes at the point where the problem actually starts.

Learn more here:
IDC Analyst Brief | Securing Open Source at Scale: How Consumption Complexity Creates Supply Chain Risk
ActiveState commissioned this IDC Analyst Brief to examine how AI coding assistants and open source consumption complexity are outpacing enterprise governance programs, and what security leaders can…
buff.ly
April 28, 2026 at 12:01 PM
Two Apache ActiveMQ CVEs are now being chained for unauthenticated remote code execution. One is already in CISA KEV. Most organizations don't know they're running ActiveMQ at all. Read more at buff.ly/xEvq0hy
#SoftwareSupplyChain #OpenSourceSecurity #CVE #DevSecOps
Apache ActiveMQ bug chain being exploited for pre-auth RCE
Found with Claude, not in KEV yet...
www.thestack.technology
April 24, 2026 at 1:45 PM
The most important number in your security program right now is not your CVE count.

It is how long your remediation sequence takes from "critical CVE identified" to "clean deployment in production."

Full read: buff.ly/EjYfOTB

#OpenSourceSecurity #CyberSecurity #AppSec
April 16, 2026 at 8:32 PM
A 27-year-old flaw in OpenBSD. A 16-year-old vulnerability in FFmpeg that survived 5 million automated tests.

AI found both in the same project.

Full read: buff.ly/EjYfOTB

#ProjectGlasswing #OpenSourceSecurity #SoftwareSupplyChain
LinkedIn Pulse
www.linkedin.com
April 16, 2026 at 4:33 PM
Project Glasswing found a 27-year-old zero-day in OpenBSD. Autonomously.

The finding problem just got solved. The remediation problem just got harder.

Industry average MTTR for a critical CVE: 60+ days. More CVEs, same infrastructure. Do the math.

buff.ly/SjD1r5R

#ProjectGlasswing #OSS
April 15, 2026 at 12:59 PM
Securing the container was never the whole answer. The application dependencies inside it were always the risk.

In 2026, that gap has a name and a price tag.

buff.ly/v5ooi3Q

#OpenSourceSecurity #SoftwareSupplyChain #CyberSecurity
April 13, 2026 at 4:56 PM
5 reasons your open source software strategy is a personal liability in 2026.
AI code volume broke the scan-and-pray model. Here's what's left exposed.

buff.ly/0QNitoA

#OpenSourceSecurity #SoftwareSupplyChain #CyberSecurity
The Five Horsemen of the AI Code Apocalypse: Why Your Current Open Source Software Strategy is a…
The era of human scale development is over. In 2026, the velocity of synthetic code generation has turned the software supply chain into a…
buff.ly
April 11, 2026 at 4:01 PM
AI pulls open source dependencies faster than humans can vet them. The perimeter was never the problem.

The ingredients were.

We broke down where application layer security actually stands in 2026.

substack.com/home/post/p-...

#OpenSourceSecurity #SoftwareSupplyChain #CyberSecurity
The Illusion of the Clean Perimeter
The modern software development lifecycle is no longer operating at human scale.
substack.com
April 10, 2026 at 1:48 PM
The axios attack highlights a gap that scanners alone can't bridge. When a hijacked credential pushes a RAT to a registry, the code has no provenance and no history. We need to pair our detection with immutable, built-from-source open source software to stay ahead.

Full story: buff.ly/xQYiHPx
April 1, 2026 at 7:03 PM
Stop pulling unverified packages from the open internet and hoping for the best. 🕸️ 📉
Hope is not a security strategy. Discover how the world's largest secure OSS catalog is replacing the chaos of the public web with a rock solid DevSecOps pipeline. 🦾
Get the blueprint: buff.ly/rTt8FLD
#SupplyChain
5 Ways the World’s Largest Secure OSS Catalog is Changing DevSecOps Forever
Open source powers 96% of modern applications, but for most DevSecOps teams, that power comes with a heavy price: vulnerability fatigue…
buff.ly
March 20, 2026 at 6:07 PM
Is your team losing 50% of its time to open source security toil?
Stop letting open source security debt kill your competitive edge. We just launched a library of 79 million secure components over 12+ language ecosystems to help you reclaim your engineering budget and ship faster.
LinkedIn Pulse
buff.ly
March 20, 2026 at 5:03 PM
96% of your code is open source. If your security strategy is just "hope and scan," you have a $1 trillion blind spot. 📉
We have unified 12+ language ecosystems into one secure golden path. 79 million components. Zero guesswork. High velocity. 🛡️🚀
buff.ly/x5DKAz6
#AppSec #OpenSource #TechTrends
March 19, 2026 at 12:30 PM
Imagine a world where your security backlog actually hits zero. 🎯
It starts by changing how you source open source. Say goodbye to the chaos of the public web and hello to a secure build pipeline that scales with you. 🛡️🦾 buff.ly/koiT8gk
#AppSec #OpenSource #TechTrends
The End of Security Debt: Why Building from Source is the Only Way to Scale
The modern software supply chain is currently functioning on borrowed time.
buff.ly
March 18, 2026 at 4:01 PM
Stop treating security debt like a mandatory tax on development. 🛑
Pulling random packages from the open internet is a gamble you do not have to take. Learn how to build secure by design and leave the patching treadmill behind for good. 🏃‍♂️💨
The future of OSS is here: buff.ly/koiT8gk
#InfoSec #Coding
The End of Security Debt: Why Building from Source is the Only Way to Scale
The modern software supply chain is currently functioning on borrowed time.
buff.ly
March 16, 2026 at 6:08 PM
The secret to elite DevSecOps? Stop chasing vulnerabilities and start preventing them. 🎯
Learn how a secure OSS catalog transforms your workflow from reactive to revolutionary. 5 shifts you cannot afford to miss. 🚀
Dive in: buff.ly/rTt8FLD
#AppSec #OpenSource
5 Ways the World’s Largest Secure OSS Catalog is Changing DevSecOps Forever
Open source powers 96% of modern applications, but for most DevSecOps teams, that power comes with a heavy price: vulnerability fatigue…
buff.ly
March 16, 2026 at 1:30 PM
Evaluating a curated OSS catalog in 2026? 🛡️ Do not just check for CVEs.

Software supply chains are now moving at machine scale and your open source security needs to keep up.

Get the full 2026 Evaluation Checklist here:
🔗 buff.ly/BDhalCI

#AppSec #DevSecOps #OpenSource
Curated Open Source Catalog Evaluation Checklist - ActiveState
2026 OSS checklist, covering security vetting, SBOM generation, SLSA compliance, supply chain transparency, and governance controls.
www.activestate.com
March 12, 2026 at 4:57 PM
Exciting news! ActiveState welcomes industry veteran Abby Kearns as our new CEO.

With 25+yrs of experience (Foundry+Puppet), Abby is set to lead our next phase of growth in securing the global software supply chain.

Read more here: buff.ly/qVGUEXH

#OpenSource #InfoSec #TechNews
March 11, 2026 at 11:10 AM
"It takes AI to beat AI... the trick is to keep humans in the loop."

@ActiveState's Bob Shaker joins @TechstrongTV to break down why the future of security is artful collaboration. Catch the full interview:
🔗 techstrong.tv/videos/lates...
Techstrong TV February 27, 2026 - Techstrong TV
Tune in to our live stream Monday through Friday for exclusive news, expert insights, and in-depth conversations with IT leaders on digital transformation, DevOps, cybersecurity, cloud-native tech,…
techstrong.tv
March 10, 2026 at 2:24 PM
Supply chain attacks have surged 300% since 2024. The old scan and fix model is officially broken. 📉

With Curated Catalogs:

✅ Eliminate 99% of CVEs
✅ Save 30 to 50% of developer time

Read more: buff.ly/fK2qkER

#DevSecOps #AppSec #CyberSecurity
March 9, 2026 at 1:29 PM
The possibilities of tech are infinite when everyone has a seat at the terminal. Today, we’re proud to celebrate the brilliant women on our team and in the global dev community.

#IWD2026 #InternationalWomensDay #OpenSource #ActiveState
March 8, 2026 at 1:01 PM
Are you ready for the EU CRA? 🛑

Don't wait for the deadline to scramble. We’ve put together a guide on the essential steps for compliance and expert advice for your teams.

Read more: buff.ly/7XqBYOu

#CyberResiliencyAct #InfoSec #AppSec #ActiveState
February 24, 2026 at 1:45 PM
With 79M components, ActiveState now offers the world's largest secure open source library, giving DevSecOps teams one stop for trusted open source.
Full details here: buff.ly/5yEBlpS #OpenSource #DevSecOps #AppSec
February 23, 2026 at 6:30 PM
We didn't just join the race; we set a new World Record. 🌎🏆

ActiveState has launched the world’s largest Secure Open Source library:
✅ 79M+ Secure Components
✅ 12+ Language Ecosystems
✅ 1st Place in Software Supply Chain Security

For More: buff.ly/5yEBlpS

#CyberSecurity #OSS
February 21, 2026 at 2:15 PM