Curated Catalog
The ActiveState Curated Catalog is a private repository of secure, pre-vetted open source components and container images, built from source with verifiable provenance and continuous remediation, designed to strengthen your software supply chain security without disrupting developer workflows.
The Curated Catalog makes the secure path the easy path for your software supply chain. By providing vetted, built-from-source artifacts with verifiable provenance, organizations can accelerate development velocity while reducing security risk and compliance overhead.
Benefits
The Curated Catalog transforms software supply chain security by making the secure path the easy path. By providing vulnerability-free, built-from-source artifacts with verifiable provenance, organizations can accelerate development velocity while reducing security risk and compliance overhead.
With a Curated Catalog, you can do the following:
- Secure Your Software Supply Chain
Replace unvetted and risky components before they reach developer or production environments with verified and continuously monitored components. - Centralize Open Source Governance with Low-Friction Guardrails
Guard how open source is selected and approved for use within your organization without introducing additional friction. Transform security policies from blockers into enablers. - Meet Open Source Compliance With Ease
Simplify compliance audits with complete visibility into open source usage across your organization, including who approved it and why it's safe. Compliance reporting moves from weeks to hours. - Reclaim Hours Lost to Development Toil
Replace hours spent on manual open source remediation tasks with time spent on new development. Engineers focus on development velocity instead of firefighting vulnerabilities.
How it works
The catalog integrates with your artifact repositories, such as JFrog Artifactory and other repository managers.

The ActiveState Build System
Once the process starts, our engineers will begin working on your build system. This process includes:
- Building packages
- Vetting dependencies
- Creating catalogs
Catalog Server
When the Curated Catalog is built, we build a catalog server for you to access. This server is your access point to your curated catalog.
Repository Manager
You can connect the curated catalog to your repository manager, such as JFrog Artifactory. This proxies your artifact manager, caches packages locally, and lets you manage package access across your organization.
Supported repository management tools include Sonatype Nexus, JFrog Artifactory, etc.
End users
Now it's time for your developers to start working with components from your secure, curated catalog. After setting up an artifact manager on their local machine, end users (developers) can install components as they normally would, using commands like pip install for Python or install.packages() in R.
Curated Catalog
The ActiveState Curated Catalog is a private repository of secure, pre-vetted open source components and container images, built from source with verifiable provenance and continuous remediation, designed to strengthen your software supply chain security without disrupting developer workflows.
Getting Started
Welcome to the ActiveState Curated Catalog. This guide will help you get up and running quickly. For more general information about the Curated Catalog, click here.
Security Feed
ActiveState Curated Catalogs come with a Security Feed. This Security Feed details all known CVEs in the provided Curated Catalog. The Security Feed empowers teams, developers, and organizations to make secure decisions about how they use open source software in their development practices.
Compatible Tools
2 items
FAQs - Curated Catalog
General Questions
Education
5 items