Machine-Speed Attacks Demand Machine-Speed Fixes: Apiiro Joins Chainguard's Athena Coalition and Makes AutoFix Free for Open Source Maintainers
Apiiro joins Athena, the Chainguard-led industry coalition for the orchestrated defense of open source software, integrates with Chainguard, and makes AutoFix free for open source maintainers.
Announcement
Published August 4 2026 · 4 min. read
Frontier models now find novel, chained zero-days in open source that survived decades of expert review, and in first-party code no one outside the company has ever read. Exploits land before disclosure. Discovery is no longer the constraint. Fixing without breaking your software is. Apiiro joins [Athena](https://www.chainguard.dev/athena), the [Chainguard](https://www.chainguard.dev/)-led industry coalition for the orchestrated defense of open source software, alongside JPMorganChase, Morgan Stanley, Cisco, Cloudflare, Akamai and other industry leaders. Apiiro and Chainguard are integrating their platforms, and [AutoFix is going free for open source maintainers](https://apiiro.com/product/guardian-agent/free-autofix), so fixes land faster and the whole community works as one team against attackers. ## Open source is half the problem Athena coordinates the ecosystem response to AI-discovered vulnerabilities and has already processed more than 40,000 findings and issued more than 2,000 patches. Through Athena, Chainguard is triaging, deduplicating, and remediating zero-day vulnerabilities that don’t yet have a CVE. Patches are provided to Athena members, and Chainguard partners with platform and cybersecurity organizations like Apiiro to shield against and surface these vulnerabilities to the broader ecosystem. Fixing open source is a shared responsibility. Fixing proprietary code is each organization's own. Both now run on the attacker's clock. ## Context decides what gets fixed Apiiro builds the [AppSec Context Graph](/platform): a software architecture graph from code to runtime for every repository, and a risk intelligence graph on top of it. Together they answer the questions that decide what happens next. Is the vulnerability reachable, in code and at runtime, inside a business-critical application? Does it combine with other risks into a toxic combination? How wide is the blast radius? **Through the integration**, Apiiro reflects Chainguard's remediation state directly in Risk Graph and assesses every finding against the customer's own software architecture. To start, this is for known CVEs that Chainguard remediates in its containers and libraries products. What Chainguard has already fixed stops showing up as an open finding, so reported risk matches real exposure. **Inside Athena**, Guardian Agent contributes the vulnerabilities it detects to the coalition. It also alerts customers the moment a coalition finding lands in their software architecture, ranks that finding by reachability, exposure and business impact, generates a contextual fix with AutoFix when code has to change, and runs the tests to prove nothing breaks. ## AutoFix, free for open source maintainers Maintainers are the reason a fix becomes permanent for everyone. They are working against a clock set by frontier models. AutoFix is free for maintainers. Unlimited AutoFixes, not a patch bot: AutoFix understands the software architecture, prioritizes by actual risk, and runs your tests before opening a clean, reviewable pull request. Unified agentic development security, for the entire open source community. Private preview announced at Black Hat. ## Securing agentic development - Chainguard provides hardened containers and malware-free language dependencies. - Athena turns one member's finding into protection the whole ecosystem inherits. - Apiiro shows which findings matter to your business, and fixes the code no one else can patch for you. AI alone does not secure software. Context does. The integration is available to joint customers today – [request a demo](/demo). Maintainers can [claim free AutoFix](/claim-free-autofix) now.
Idan Plotnik