CI/CD Pipelines

Secure Packages at the Build Step

ActiveState components integrate into your CI/CD pipeline at the point where dependencies are resolved. Your build configuration pulls from a vetted source instead of a public registry, and nothing else changes.

How it works

Point your package manager or container registry configuration at your Curated Catalog. When your pipeline runs, it resolves dependencies from ActiveState's vetted catalog instead of public sources. This works with any CI/CD platform that supports standard package manager configuration.

FAQs

Still have questions?

Talk to our team.

Does ActiveState require a CI/CD plugin?

No. ActiveState integrates through standard package manager and registry configuration. Any CI/CD platform that can run pip, npm, Maven, or pull container images can use ActiveState.

What happens when ActiveState remediates a package my pipeline depends on?

ActiveState rebuilds the package with the patch applied and publishes it to your catalog. Your pipeline picks up the updated package on its next run through normal dependency resolution.

Secure Your CI/CD Pipeline

Talk to our team about connecting your Curated Catalog to your CI/CD workflows.