Partnering with Chainguard to secure AI-speed open source delivery
Share on socials
Adaptavist partners with Chainguard to secure the open source foundation of AI-speed software delivery

The Adaptavist Group
Published on 11 August 2026
10 min read


The Adaptavist Group
Published on 11 August 2026
10 min read
Jump to section
Jump to section
The CVE backlog no one can outrun
Where Adaptavist comes in
What this means for engineering, security, and the business
Building at AI speed, without the risk
New partnership brings Chainguard's catalogue of trusted, hardened open source software to Adaptavist customers, closing the gap between engineering velocity and supply chain security.
Enterprise engineering teams have spent the last decade removing friction and becoming very good at shipping fast. Modern CI/CD pipelines, cloud-native architectures, RESTful APIs and now AI-assisted development have compressed release cycles that used to take months into days. A lot of that speed comes from the open source components both your software and pipelines consume - the base images, libraries, and packages that make up the vast majority of any modern codebase. The evolving software supply chain threat landscape and industry initiatives such as Athena are bringing software supply chain security to board-level attention.
For most organisations, "open source" still means "unpatched by default." Vulnerability scanning tells you what's wrong after you've already pulled the dependency into a build. Remediation becomes a permanent tax on engineering time rather than a one-off fix, and in regulated industries, including financial services, the public sector, and critical infrastructure, that tax is compounding exponentially as AI accelerates both the volume of code being written and the sophistication of the attacks targeting it.
Today, we're excited to announce a new partnership with Chainguard, the trusted source for open source, to help our customers close that gap; embedding security at the very first dependency pull rather than bolting it on after the fact, and giving engineering teams back the huge amounts of time currently lost to CVE remediation.
The CVE backlog no one can outrun
Ask most engineering leaders where their time actually goes, and vulnerability patching is rarely the answer they want to give. Yet research from large enterprise deployments suggests CVE remediation and related compliance activity consumes 15–20% of total engineering effort: capacity that isn't going toward new features, new markets, or competitive response, but toward chasing a backlog that regenerates faster than it can be cleared, and critically, someone else controls.
This creates a familiar three-way tension inside customer organisations. Engineering wants developer velocity back. Security wants standardisation, provenance, and lower exposure. Product leadership wants to ship faster without taking on more risk. Traditional vulnerability scanning doesn't resolve any of these; it just tells you, after the fact, how far behind you already are.
Regulation is tightening the timeline, too. The EU Cyber Resilience Act introduces mandatory security-by-design and vulnerability-handling requirements for any product with digital elements sold into the EU, including the open-source components within it, and with reporting obligations for actively exploited vulnerabilities set to take effect in September 2026. Combined with existing pressure from EU DORA, FIPS, FedRAMP, and PCI DSS, the message for regulated enterprises is the same: an accurate SBOM and a defensible patching process are no longer optional, and securing the software supply chain is an urgent priority.
At the same time, AI is raising the stakes on both sides of the equation. Developers and coding agents are pulling in open-source dependencies faster and with less manual review than ever, widening the attack surface at exactly the moment attackers are gaining access to AI tooling that can find and chain vulnerabilities far faster than manual methods ever could. Frontier coding models are increasingly capable of understanding codebases well enough to spot hidden or cumulative flaws from a simple instruction — a capability that's transformative for legitimate engineering work, but one that also lowers the bar for exploiting the weak fundamentals many organisations have long tolerated as acceptable risk. Boards are taking notice, and vulnerability management is moving from a technical footnote to a funded, board-level priority.
Prevention, not just detection
Chainguard's approach is to remove the vulnerability before it ever reaches your pipeline, rather than alerting you to it once it has. Its containers, libraries, and OS packages are continuously rebuilt from verified sources into hardened environments, functioning as drop-in replacements for the public registry images and packages most teams already depend on, with Chainguard reporting an average 98% reduction in vulnerabilities for customers who make the switch, and more than 600 agencies and enterprises already rely on it.
Chainguard calls this "start left" security: not just shifting security earlier in the pipeline, but embedding it from the very first line of code and the very first dependency pulled. Through this partnership, that protection now spans the full software delivery lifecycle our customers already work across:
- Hardened containers and libraries — thousands of continuously rebuilt, minimal-CVE (and lightweight) container images and malware-resistant drop-in replacements for common Python, Java, and JavaScript packages, so teams inherit a clean foundation without changing how they build, and execute faster too.
- Secured CI/CD and agentic workflows — protection extending into the pipelines and AI coding agents now writing and shipping code, so the growth in AI-assisted development doesn't come with a growth in unobserved and unmanaged risk.
- Continuous, provenance-backed rebuilds — automated re-evaluation of dependency graphs and full rebuilds from source, giving security and compliance teams verifiable evidence rather than a point-in-time snapshot.
Where Adaptavist comes in
Licensing Chainguard is the easy part. The real barrier most enterprises face is organisational: fragmented artefact management, inconsistent container practices, security and engineering teams that have historically operated in silos, and years of accumulated technical debt that make a clean cutover harder than it sounds. That's the gap Adaptavist's DevOps and DevSecOps practice is built to close.
As Paul Cavanagh, Field CTO at Adaptavist, puts it:
"Every engineering organisation we talk to is fighting the same losing battle, spending a fifth of their capacity patching vulnerabilities in software they didn't write and can't fully see into. Chainguard flips that model from detection to prevention, and our job is to make adopting that shift as fast and painless as possible: getting customers migrated into a trusted repository, re-pointing their upstreams, and proving the time and risk reduction back to the business. Mythos and Athena have elevated the conversation around supply chain security from a technical and efficiency discussion overnight to a board-level risk management imperative. The fact that Chainguard is a founding member of Athena is, for me, recognition of their differential capabilities and market leadership in addressing this existential threat."
Our services wrap around the technology from strategic advisory on platform architecture and security posture, to hands-on technical integration and migration support, including moving customers into centralised (and verified) artefact management and repointing existing pipelines to Chainguard sources, with phased enablement and adoption designed to help engineering teams achieve fast time-to-value without disrupting delivery.
"Making software secure by default requires more than great technology—it requires great partners," said Naveen Sharma, Global Vice President of Partnerships at Chainguard. "Adaptavist brings the technical expertise and customer proximity to help organisations operationalise trusted software at enterprise scale, enabling developers to innovate with greater speed and confidence."
What this means for engineering, security, and the business
For developer experience and platform teams, this is time reclaimed: less CVE firefighting, more capacity spent on the work that actually moves the roadmap forward.
For security and compliance teams, it's a shift from chasing evidence to holding it by default: continuous, provenance-backed rebuilds instead of periodic scans, mapped against the frameworks (CRA, DORA, FIPS, SOC 2) that already dominate the audit calendar.
For engineering leadership, it's a rare case where the business case is genuinely straightforward: fewer vulnerabilities, reduced attack surface, less remediation overhead, and developer hours returned to revenue-generating work. All supporting a robust and essential foundation that enables you to accelerate your AI-led software engineering strategy whilst actively managing and mitigating security and risk.
Building at AI speed, without the risk
The pace of AI-driven development isn't slowing down, and neither is the diversity and sophistication of the threats targeting your open source consumption. Through this partnership, we're helping customers stop treating vulnerability remediation as a permanent and reactive cost of doing business and start building on a solid foundation that's secure from the first dependency pull.
Ready to take the next step?
Speak to our DevOps experts to find out what a Chainguard-secured software supply chain could look like for your organisation.
Written by
