Chainguard State of Trusted Open Source 2025

Chainguard State of Trusted Open Source 2025

The State of Trusted Open Source report reveals that most vulnerabilities lie outside the top 20 most popular open source projects, highlighting the security challenges in the β€œlongtail” of less-visible images. Speedy remediation, compliance-driven adoption, and the growing importance of AI-related stacks like Python are key themes shaping modern open source security. #Chainguard #FIPS #Python #OpenSourceLongtail

Keypoints

  • The report is structured with sections covering usage patterns, regional differences, longtail image importance, compliance impacts, CVE risk distribution, remediation speed, and concluding with a call for broad trusted open source coverage.
  • Key statistics include analysis of over 1800 container projects, 10,100 vulnerability instances, and 154 unique CVEs recorded from September to November 2025.
  • Python leads as the most popular open source image globally, driven by AI workloads, followed by Node, nginx, Go, and Redis, indicating a foundational stack focused on modern infrastructure and AI development.
  • Longtail images beyond the top 20 projects constitute roughly half of production usage and host 98% of all vulnerabilities remediated, emphasizing the security risks outside widely-used images.
  • Compliance needs, especially FIPS usage by 44% of customers, strongly influence production image choices, underscoring regulatory pressure as a catalyst for trusted open source adoption.
  • Chainguard achieves rapid remediation times for vulnerabilities, resolving Critical CVEs in under 20 hours on average and significantly faster than SLA targets.
  • The report highlights a disconnect where engineering teams focus on popular projects while the majority of risk accumulates in less-visible dependencies, advocating for comprehensive vulnerability management across the entire open source supply chain.
  • Trust in open source is linked to the ability to quickly remediate vulnerabilities across all images, including both popular and longtail projects, rather than just the core stack.
  • The findings call for solutions like Chainguard that manage the operational burden of the longtail, ensuring scalable security coverage as open source supply chains become more complex.
Chainguard-State-of-Trusted-Open-Source-2025
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)

Download Report from Github