Manifest Joins Chainguard’s Athena Coalition to Find Open-Source Risk Inside Software Products

Manifest will help Athena members rapidly identify the blast radius of new vulnerabilities across open-source packages, third-party products, binaries, and other software across enterprise supply chains.



WASHINGTON--(BUSINESS WIRE)--#AI--Manifest Cyber, a leader in software and AI supply chain security, today announced it has joined Athena, the Chainguard-led industry coalition for the orchestrated defense of open-source software. Manifest joins JPMorganChase, Morgan Stanley, Cisco, Cloudflare, Akamai, and PwC in the coalition, where it will bring its software supply chain illumination capabilities to help members rapidly assess the blast radius of new vulnerabilities across their internal and third-party software.

Athena gathers vulnerability findings from across its membership, builds hardened fixes under embargo, stacks platform and network protections around them, and drives durable fixes upstream. Chainguard reported on July 7, 2026 that the coalition had processed more than 40,000 findings in its first three weeks, 42% of them critical or high severity.

A hardened rebuild closes the problem fast where a team controls the build, and Athena stacks platform mitigations and vendor detections behind it for everything else. But a hospital whose exposure sits inside an infusion pump has no rebuild to take. Neither does a utility running a controller that shipped years ago with no bill of materials. The response there is isolation, a compensating control, or a call to the vendor, and all three start with knowing which product carries the component.

Manifest is proud to bring its core functionality to Athena to help secure open-source and vendor-provided software, including:

  • Binary analysis of shipped commercial software. Manifest analyzes a product with no source code available and reports the open-source components and third-party dependencies inside it. Results persist, so the next Athena record gets checked against what Manifest already knows instead of starting over.
  • Reachability for applications. Manifest reports whether an application calls the vulnerable code, so members spend embargo time on real exposure rather than on every new record.
  • Continuous monitoring of first- and third-party software. Most third-party risk programs run on questionnaires and point-in-time reviews. Manifest rechecks supplier software as new findings arrive and reports which suppliers, products, and systems are affected.
  • Foreign contributor risk. Manifest flags foreign ownership, control, and influence exposure across open-source contributors and suppliers.

Daniel Bardenstein, CEO of Manifest, said: "Athena is effectively using powerful AI models to identify and patch vulnerabilities in open-source projects. For developers, bringing in hardened packages is straightforward. But those packages run inside medical devices, network hardware, cars, and other critical technologies that power our society. Manifest’s involvement in Athena will address that exact gap: making it easy to take action on those disclosed vulnerabilities, identify affected systems, and ensure organizations, and the people they serve, are protected."

"We built Athena because orchestrated defense is the only thing that keeps pace with AI-powered attacks. No single defender can cover the entire open-source ecosystem alone. Manifest illuminates open-source risk inside first-party, third-party and AI products, bringing a uniquely valuable contribution to Athena," said Naveen Sharma, Global Vice President of Partnerships, Chainguard.

Learn more about Athena at chainguard.dev/athena and about Manifest at manifestcyber.com.

About Manifest

Manifest is the leading platform securing the entire AI and software supply chain, from source code to models to third-party software. We empower product security and third-party risk teams to operate critical systems and applications with confidence by detecting and managing hidden software supply chain and AI risks at scale. The Manifest Platform provides end-to-end visibility and control across Product Security, AI Risk, and Supplier Risk, helping teams build secure, trusted software without losing velocity. Organizations across defense, healthcare, automotive, and other regulated industries trust us to strengthen product and AI security, reduce third-party risk, and support compliance. Learn more at manifestcyber.com.

About Athena

Athena is an industry coalition for the orchestrated defense of open-source software, announced by Chainguard on June 16, 2026. Members submit pre-disclosure vulnerability findings to a shared platform, which carries each finding from discovery to a durable upstream fix. Learn more at chainguard.dev/athena.


Contacts

Alejandra Diaz Valdes, Head of Operations, ale@manifestcyber.com