Manifest Cyber has joined Athena, the Chainguard-led coalition for the orchestrated defense of open-source software. We're excited to join a powerhouse program with companies like JPMorganChase, Morgan Stanley, Cisco, Cloudflare, and Akamai.
After two years at Chainguard building hardened containers, I know that product well. I also know the story customers tell us every day. A vulnerability lands in third-party software they cannot update themselves, and they have to find where it sits in what they ship. That is where Manifest helps, and it is what we bring to Athena.
Why we care
I worked on the whole image catalog, Custom Assembly, the Guardener, and improving software bills of materials (SBOMs). A rebuilt, minimal, current artifact is the best answer to a vulnerability anyone has shipped. When a customer could take the rebuild, the problem went away, usually before anyone opened a ticket.
What about a hospital security team? What about their infusion pumps, imaging workstations, and the building management controllers in the basement? No upstream release to pull, usually no source to read, and a vendor who might answer next quarter.
This team isn't out of options. Isolate the device. Put a control in front of it. Push the vendor for a straight answer. But, each one starts with knowing which box the component is in, and finding that box is the work Manifest does.
What happens when the fix is unreachable
A fix does not reach every system running the code. Athena accounts for that, which is why the coalition has partners like us in it.
Naming the box sounds easy. It is not. Most teams I have worked with need weeks, because the answer is split across scanners that each see one slice and none of them read the vendor binaries.
Three things we do with an Athena record, in order
- Start with the software members bought. When a vendor will not or cannot say what is inside a product, we work from the shipped binary. No source required. We name the appliance, device, or application that carries the component, and we keep that analysis, so the next record starts from what we already know.
- Narrow the list where the code is available. For applications written in Python, JavaScript, and Go, reachability tells you whether the application calls the vulnerable code. A finding in a dependency nothing ever calls is not where an embargo week should go.
- Support the decision during the embargo. Which product to isolate, which compensating control applies, which deployment to hold. With evidence behind each call, because there is no public advisory to point at when someone asks why you pulled a device out of service.
Most third-party risk programs run on questionnaires that tell you what a supplier said last year. We recheck supplier software as new findings arrive, and we flag foreign ownership, control, and influence exposure across contributors and suppliers.
Why a coalition
Do not build what you can buy unless it is core business value. Nobody's core business value is privately forking the same library that 11 other companies are also forking, badly, with no shared record of what got fixed. Athena is the alternative, and we tell members where the risk sits inside the third-party software they run.
Athena is finding vulnerabilities in packages more than five years old, mature code that survived years of expert review. Those packages are not only in containers. Some sit inside a box in a hospital basement. Somebody has to open that box, and that is why we joined.
Interested in learning more? Send an email to us at info@manifestcyber.com.




