The State of Trusted Open Source report reveals that most vulnerabilities lie outside the top 20 most popular open source projects, highlighting the security challenges in the βlongtailβ of less-visible images. Speedy remediation, compliance-driven adoption, and the growing importance of AI-related stacks like Python are key themes shaping modern open source security. #Chainguard #FIPS #Python #OpenSourceLongtail
Keypoints
- The report is structured with sections covering usage patterns, regional differences, longtail image importance, compliance impacts, CVE risk distribution, remediation speed, and concluding with a call for broad trusted open source coverage.
- Key statistics include analysis of over 1800 container projects, 10,100 vulnerability instances, and 154 unique CVEs recorded from September to November 2025.
- Python leads as the most popular open source image globally, driven by AI workloads, followed by Node, nginx, Go, and Redis, indicating a foundational stack focused on modern infrastructure and AI development.
- Longtail images beyond the top 20 projects constitute roughly half of production usage and host 98% of all vulnerabilities remediated, emphasizing the security risks outside widely-used images.
- Compliance needs, especially FIPS usage by 44% of customers, strongly influence production image choices, underscoring regulatory pressure as a catalyst for trusted open source adoption.
- Chainguard achieves rapid remediation times for vulnerabilities, resolving Critical CVEs in under 20 hours on average and significantly faster than SLA targets.
- The report highlights a disconnect where engineering teams focus on popular projects while the majority of risk accumulates in less-visible dependencies, advocating for comprehensive vulnerability management across the entire open source supply chain.
- Trust in open source is linked to the ability to quickly remediate vulnerabilities across all images, including both popular and longtail projects, rather than just the core stack.
- The findings call for solutions like Chainguard that manage the operational burden of the longtail, ensuring scalable security coverage as open source supply chains become more complex.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)