Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 14, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 14, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 14, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 14, 2025

      I test a lot of AI coding tools, and this stunning new OpenAI release just saved me days of work

      May 14, 2025

      How to use your Android phone as a webcam when your laptop’s default won’t cut it

      May 14, 2025

      The 5 most customizable Linux desktop environments – when you want it your way

      May 14, 2025

      Gen AI use at work saps our motivation even as it boosts productivity, new research shows

      May 14, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Strategic Cloud Partner: Key to Business Success, Not Just Tech

      May 14, 2025
      Recent

      Strategic Cloud Partner: Key to Business Success, Not Just Tech

      May 14, 2025

      Perficient’s “What If? So What?” Podcast Wins Gold at the 2025 Hermes Creative Awards

      May 14, 2025

      PIM for Azure Resources

      May 14, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Windows 11 24H2’s Settings now bundles FAQs section to tell you more about your system

      May 14, 2025
      Recent

      Windows 11 24H2’s Settings now bundles FAQs section to tell you more about your system

      May 14, 2025

      You can now share an app/browser window with Copilot Vision to help you with different tasks

      May 14, 2025

      Microsoft will gradually retire SharePoint Alerts over the next two years

      May 14, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»ActiveState relaunching its platform for open source management

    ActiveState relaunching its platform for open source management

    November 15, 2024

    ActiveState today announced it is rebranding and relaunching its product as an open source management platform to help enterprises manage open source complexities, ensure supply chain security, and streamline DevSecOps. The platform, which integrates with existing tools, aims to proactively manage open-source risks by providing tools for discovery, analysis, remediation, and governance. 

    It offers a centralized dashboard to track open-source usage, policy enforcement, and vulnerability management. The platform also ensures reproducible builds and streamlines upgrades, reducing the burden on developers.

    Scott Robertson, ActiveState’s CTO, explained that most people know of ActiveState for its management of open source dynamic programming languages. “That usually became the way they got introduced to ActiveState’s real core vision, which is helping enterprises manage open source, the complexities of open source at scale that included managing licenses, vulnerabilities and doing very complex builds,” he said. “This announcement … is about us taking all of the tooling that we’ve created over the last 20 years and turning that into sets of platforms and tools that they can run themselves in their own environments.”

    The driver behind the changes at ActiveState is the fact that software applications today are less secure than they ever have been. Stephen Baker, CEO at ActiveState, said the reason for that is that 96% of all applications contain open source, and malware last year was discovered in 245,000 open source packages, more than three times the amount discovered in the previous three years combined. 

    Meanwhile, of the organizations that are building and consuming these applications, about 59% have claimed to have taken steps to secure their software supply chains. In spite of that, the cost of targeted software supply chain attacks are expected to double by 2030, to about $140 billion, Baker said.  “The root cause of all of this is that organizations are not proactively managing the open source they consume,” he explained. “It is very much a ‘set it and forget it’ mentality. Very rarely [are developers] going to go back in and opening up that application to upgrade the open source that’s been embedded in there. So they’re sort of happy to let this old open source fester and rot and become less secure over time.”

    Further, Baker noted that in a recent survey, 81% of developers admitted they have shipped code with known open source vulnerabilities because it’s the fastest path to meeting deadlines and shipping the product.

    The stance ActiveState has taken is that organizations need to become much more proactive in how they manage open source, using tools to enforce policies that cause the least amount of disruption to the development process and foster greater collaboration, he said.

    The tool chain ActiveState has built to help its customers manage open source consumption is what has been productized and made available today. “We’re now giving the tools to every DevSecOps team to manage their own open source that they’re consuming in a much more scalable format and a much more secure format, in a manner that is going to improve the application security posture, while at the same time, not destroying developer productivity,” Baker said.

    The platform is built on automation to provide timely insights into how vulnerable your open source is, and what you need to do to make it less vulnerable, hence eliminating 90% of the undifferentiated heavy lifting that every developer needs to do to research the dependencies, understand how they need to be upgraded and how risky they are, Baker pointed out. “One way to think about it is, it is open source supply chain security in a box. It is a turnkey platform that integrates with existing developer tools in order to help keep the open source current and more secure.”

    Among the capabilities of new ActiveState Open Source Management Platform, according to director of product Pete Garcin, are:

    • The ability to discover open source as you’re running it, from various sources, and monitor it through a single pane of glass. “Whether that’s scanning your Kubernetes cluster or importing from your GitHub repo or letting you ingest an SBOM (software bill of materials) or a requirements file – however it’s spread across your organization – allows you to aggregate that and collect it so you have that centralized dashboard that shows all the open source that’s running inside my organization and everywhere that it’s running,” he said.
    • Tools to help analyze and prioritize the state of the risks in your organization, which show “what vulnerabilities do I have, what licenses do I have, what breakdown by language ecosystems do I have, with a total across your organization of the composition of all your software,” Garcin said.
    • Tools for policy and governance, as well as an immutable catalog of open source packages  indexed from across the internet. ” With our platform, it’s always reproducible, and you can go back at any point, and that’s combined with policies that allow you to curate that catalog so that you can ensure that anything that people are pulling is always going to be in compliance with whatever sort of governance you put in place.”

    Robertson said this capability is the key differentiator between ActiveState and everyone else in the market. “Everybody else is in this kind of reactive model, where developers assemble something, get it all the way through CI/CD, and then they bring in their scanning tools to figure out what they have consumed. We come into play before that. We come in at assembly time. We’re applying all the rules and policies even before it gets into your organization, so that you’re consuming things cleanly at the point where you’re building the application.”

    Baker offered a saying to summarize the issue and the solution: “You can’t deny the fact that every organization on the planet is now dependent on open source, and threat actors and cyber attackers are now depending on the lack of organizational controls on open source to plan their next attack.” 

    The post ActiveState relaunching its platform for open source management appeared first on SD Times.

    Source: Read More 

    news
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleJetBrains reveals 2024.3 releases of its AI Assistant and IDEs
    Next Article PHPxWorld – The resurgence of PHP meet-ups with Chris Morrell

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 15, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-30419 – NI Circuit Design Suite SymbolEditor Out-of-Bounds Read Vulnerability

    May 15, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Learning Elastic Costs to Shape Monge Displacements

    Development

    NVIDIA Omniverse Cloud Sensor RTX simulates physical sensors so that developers can test autonomous machines

    Development

    Rilasciata BleachBit 5.0: la nuova versione del software open source per la pulizia di sistema su GNU/Linux

    Linux

    Binary Tree Diameter: Algorithm and Implementation Guide

    Development

    Highlights

    Development

    U.S. Sanctions Chinese Cybersecurity Firm for State-Backed Hacking Campaigns

    January 4, 2025

    The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Friday issued sanctions against…

    Over 145,000 Industrial Control Systems Across 175 Countries Found Exposed Online

    November 21, 2024

    Responsible AI in action: How Data Reply red teaming supports generative AI safety on AWS

    April 29, 2025

    Best 3D Photoshop Actions for Stunning Depth Effects

    August 13, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.