Key Takeaways
- SBOMs provide visibility into your software components, but they do not control what enters your environment or prevent risk from being introduced.
- Provenance strengthens trust by verifying how components are built and sourced, but without enforcement it remains a partial solution.
- Coverage gaps and fallback to public registries reintroduce unmanaged risk, even in otherwise secure supply chain models.
- A curated catalog shifts security upstream by enforcing trusted, built-from-source components at the point of ingestion.
According to the Linux Foundation’s State of Open Source Software report, only 34% of organizations have defined a clear open source strategy. At the same time, the report also found that 83% believe open source is critical to their future, and 72% say it makes them more competitive.
This is important because most organizations are betting their software, their velocity, and ultimately their market position, on open source.
Without a clear model for controlling the risk that comes with it, what happens when that risk materializes?
An evident lack in open source strategy is what drove the rise of SBOMs. For the first time, teams could see what was inside their software. They could inventory components, identify vulnerabilities and respond to audit requirements with something more concrete than guesswork.
But as we’ve explained before, visibility is not the same as control, and while SBOMs can tell you what made its way into your application environment, they can’t tell you whether it should even be there in the first place.
Today, the gap between believing you need an open source strategy and actually implementing one is only widening. AI is now generating code faster than teams can validate it, which introduces dependencies at a pace that breaks traditional (and let’s face it, manual) review processes.
To counter this, the industry shifted towards open source provenance. But while signed artifacts and SBOMs are important, if your coverage is incomplete or your developers still fall back to public registries when something is missing, you are not in control of your supply chain security.
This is where the curated catalog comes in.
Put simply, a curated catalog is an enforcement model. It ensures that only trusted, built-from-source, continuously maintained components ever enter your environment in the first place.
In this article, we explore how a Curated Catalog like Active State’s Curated Catalog, which you can explore here) can strengthen your software supply chain security.
SBOMs Show You the Problem. Provenance Starts to Solve It.
Once SBOMs are in place, most teams run into the same problem: The list of open source components keeps growing.
New dependencies are introduced faster than they can be reviewed, for example, and remediating open source vulnerabilities can often get deprioritized or delayed in favour of things like a bug fix. Over time, SBOMs really just become a mere record of accumulated risk.
The principle of provenance, then, was introduced to change that dynamic. Instead of asking what is in your software, provenance asks whether an artifact can be trusted at all. Was the component built from a verified source? Was the build process reproducible? Can the artifact be traced, validated and verified through signed metadata?
Standards like the SLSA Level 3 formalize these expectations, raising the baseline for what “trusted software” should look like.
But the challenge with provenance is it’s still a selective mechanism for retaining control over a software supply chain. Developers, for instance, can still pull from unverified sources when something is missing, and if coverage does not extend across your full stack, you are still operating in a mixed-trust environment.
What Does a Curated Catalog Actually Deliver?
A curated catalog changes things. At its core, a curated catalog is a pre-vetted set of open source components that have already been built from source, verified and approved for use.
Because engineers can operate in a safe and closed-loop repository, there’s no fallback to public registries when a package is missing, and therefore no ambiguity about where a component came from or how it was built.
Every (and we mean every) dependency is sourced from a controlled environment, signed and maintained over time, rather than scanned once and left to rot inside of an application. So, with near-complete ecosystem coverage like this, your engineering teams no longer have to choose between a secure package and a practical, easy-to-implement package. Moreover, your developers aren’t forced to step outside of this repository to get their work done, which means the system itself can be controlled, enforced, trusted.
The outcome is a fundamental shift in posture, and your teams can now define security at the point of ingestion, rather than applying it after dependencies have entered your environment.
The ActiveState Edge: What Happens When Provenance, Coverage and Remediation Work Together?
Most approaches to enterprise supply chain security solve one part of the problem well. And we’re talking really well. They verify builds, they generate SBOMs, or they introduce stronger signals of trust.
But enterprise environments are not built on signals of trust, they’re built on guarantees, and this is where ActiveState separates itself from the crowd.
First, scale. With more than 79 million open source components across ecosystems, coverage is not a constraint. Engineering teams are not forced into finding workarounds or fallback paths that only exist on public registries.
Second, continuous management. Critical vulnerabilities are addressed within a five-day critical, 10-day high SLA contract, meaning fixes are delivered upstream in a predictable window. That removes the operational burden from internal teams and replaces it with accountability.
Finally, integration. ActiveState integrates directly with the tools your teams already rely on, including JFrog, Nexus, AWS, Azure and GitHub. Our Curated Catalog fits into existing workflows as a drop-in layer and not a disruptive process change.
Where other solutions provide a foundation, ActiveState delivers a production-ready system, one that does not require tradeoffs between coverage, velocity and security.
Explore the ActiveState Platform
Greater Control Is the Strategy
SBOMs gave your teams visibility. Provenance raised the bar for trust. But neither, on their own, gives you control.
And when it comes to software supply chain security, control is the strategy.
If your teams are still pulling from public registries, or if coverage does not extend across your full stack, then your supply chain is still wide open to risky vulnerabilities.
A curated catalog closes that loop.
If you want to understand what that looks like in practice, contact us and see how a curated catalog can strengthen your software supply chain from the inside out.
Frequently Asked Questions
What is a curated open source catalog?
A curated open source catalog is a governed repository of vetted packages that have been rebuilt, scanned, signed, and continuously maintained before developers can install them.
.png)
.png)
.png)