Security You Should Know Security You Should Know

Securing the Open Source Supply Chain with ActiveState

Jul 20, 2026 · 18m

Summary

Host Rich Straffolino interviews ActiveState CEO Abby Kearns, alongside Doug Mayer and Howard Holton, on open source supply chain security. They discuss how AI accelerates vulnerability discovery and the risks of public registries. ActiveState offers a verified package catalog to reduce CVEs and streamline remediation. The episode also covers SBOM attestation, regulatory pressures like the EU CRA, and the strain on open source maintainers.

Topics discussed

Introduction and the rise of open source supply chain risks ActiveState's value proposition and pricing model Maintaining developer velocity with secure catalogs Differentiating from JFrog and CloudSmith Securing AI-assisted development workflows Handling missing packages and friction in the process SBOM attestation and the shadow AI challenge Regulatory pressures: EU CRA and GDPR comparisons Understanding the ActiveState catalog structure Open source maintainer crisis and episode wrap-up
Listen ad-free on Castria