Securing the Open Source Supply Chain with ActiveState
Jul 20, 2026 · 18m
Summary
Host Rich Straffolino interviews ActiveState CEO Abby Kearns, alongside Doug Mayer and Howard Holton, on open source supply chain security. They discuss how AI accelerates vulnerability discovery and the risks of public registries. ActiveState offers a verified package catalog to reduce CVEs and streamline remediation. The episode also covers SBOM attestation, regulatory pressures like the EU CRA, and the strain on open source maintainers.
Topics discussed
Introduction and the rise of open source supply chain risks
ActiveState's value proposition and pricing model
Maintaining developer velocity with secure catalogs
Differentiating from JFrog and CloudSmith
Securing AI-assisted development workflows
Handling missing packages and friction in the process
SBOM attestation and the shadow AI challenge
Regulatory pressures: EU CRA and GDPR comparisons
Understanding the ActiveState catalog structure
Open source maintainer crisis and episode wrap-up
Listen ad-free on Castria