Security Stack Logo
ActiveState Curated Catalog logo

Application SecuritySupply Chain Security

ActiveState Curated Catalog

Private catalog of vetted, built-from-source open source components with SLA-backed CVE remediation

ActiveState Curated Catalog Overview

What it does

ActiveState Curated Catalog is a software supply chain security product that gives enterprises a private, vetted source for open source components, replacing direct pulls from public registries such as PyPI and npm. Security and engineering teams set policy guardrails at the point of ingestion, while developers and AI coding assistants keep consuming packages through pip, npm, and their existing package managers. Every component is built from original source code in Supply-chain Levels for Software Artifacts (SLSA) Level 3 infrastructure with cryptographic attestation on each artifact.

How it works

The catalog draws on the ActiveState Library, a corpus of 79 million components spanning 12 language ecosystems including Python, Java, JavaScript, Go, R, and .NET. ActiveState compiles each component from source in its hardened build environment, signs it, and delivers native artifacts such as Python wheels and Java JARs into existing artifact repositories. A component-level security feed updates every 24 hours; when an upstream fix lands, affected components are rebuilt and republished under a contractual SLA of 5 business days for critical CVEs and 10 for highs, with breaking-change analysis run before updates ship.

Credentials and traction

SOC 2 Type II certified, with the audit report available through the ActiveState Trust Center. ActiveState was positioned as a Niche Player in the inaugural 2026 Gartner Magic Quadrant for Software Supply Chain Security, and the Curated Catalog was named Best Open Source Security Platform in The Hacker News Cybersecurity Stars Awards 2026. Customers include Barclays, Moody's, Siemens, Druva, and Mercury Financial, and the company has supplied enterprise open source tooling since 1997.

Key Capabilities

mapped to solution categories
SBOM Management

Searches the organization-wide SBOM inventory by component, version or CVE and returns the affected products, projects and environments, so a newly disclosed vulnerability or a suspect package can be traced to everywhere it ships.

Creates, imports, and manages Vulnerability Exploitability eXchange statements asserting the exploitability status of CVEs for specific product versions, reducing false positive noise for downstream consumers.

Generates SBOMs from source code analysis (via build system integration), and from binary analysis (via binary composition analysis), the latter enabling SBOM generation for third-party software where source is unavailable.

Generates formatted evidence packages for SBOM-related regulatory requirements: FDA pre-market cybersecurity guidance, Executive Order 14028 SBOM requirements, EU Cyber Resilience Act Article 13.

Tracks license obligations across the SBOM inventory, identifying GPL and AGPL copyleft propagation, license conflicts, and FOSS obligations for each release.

Monitors SBOMs against live vulnerability feeds, alerts when new CVEs affect components in managed SBOMs. Latency to alert after new CVE publication varies.

Imports and exports SBOMs in CycloneDX, SPDX, and SWID formats, enabling interoperability with scan tools, procurement workflows, and regulatory evidence systems.

Software Supply Chain Security

Governs third-party software consumption to apply consistent software supply chain security policy.

Risk context for open-source dependencies including reachability, exploitability, and upgrade impact.

Verification of build integrity and artifact provenance through signing, attestation, and change attribution.

Compliance

certifications
GDPRSOC 2 Type II

Integrations

compatible tools
AWS CodeArtifactAzure ArtifactsClouderaGitHub PackagesGitLab Package RegistryJFrog ArtifactorySonatype NexusTrivyWiz

Implementation & support

Deployment model
SaaS
Support channels
DocumentationTicketing PortalTraining / Academy

Info last updated on September 7, 2026

Buyers

See how ActiveState Curated Catalog fits your stack

Add ActiveState Curated Catalog to your shortlist and unlock all evaluation tools.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.