# The State of Trusted Open Source: December 2025

DevFeed: [The State of Trusted Open Source: December 2025](<https://devfeed.tech/articles/the-state-of-trusted-open-source-december-2025-13270.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-state-of-trusted-open-source-december-2025>)

Published: 2025-12-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cves](<https://devfeed.tech/tags/chainguard-cves.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-report](<https://devfeed.tech/tags/chainguard-report.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve-data](<https://devfeed.tech/tags/cve-data.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [state-of-trusted-open-source](<https://devfeed.tech/tags/state-of-trusted-open-source.md>), [trends](<https://devfeed.tech/tags/trends.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

Chainguard's December 2025 State of Trusted Open Source report examines open source usage, CVE data, vulnerability remediation, and compliance trends across its customer base and container image catalog. It highlights Python's role in AI workloads, the prevalence of longtail images in production, the concentration of remediated vulnerabilities outside the top 20 projects, FIPS image usage, and remediation of Critical CVEs in under 20 hours on average.

## Source excerpt

Chainguard's State of Trusted Open Source for December 2025 dives into usage trends for Chainguard Containers, CVE data, and why remediation speed matters.