
Securing the Source: Navigating AI Velocity, CRA Compliance, and Dependency Debt with Abby Kearns
Om avsnittet
In this episode of What’s in the SOSS, host Sally Cooper sits down with technology executive and ActiveState CEO Abby Kearns to break down the rapidly evolving open source security landscape. Together, they dissect why reactive post-build scanning fails to prevent dependency debt, how machine-speed AI ingestion is overwhelming human maintainers, and what the impending EU Cyber Resilience Act (CRA) mandates mean for enterprise software supply chains. Abby offers actionable insights into why building a "start secure, stay secure" paradigm is essential for modern software pipelines and why open source communities must unite to redefine repository economics in an AI-dominated world.
Chapters:
- 00:00 - Introduction: Sally Cooper welcomes Active State CEO Abby Kearns to discuss AI, vulnerability management, and open source security.
- 01:27 - The Limits of Reactive Scanning: Why controlling components at the build source beats post-build scanners.
- 04:26 - AI Agents and Ingestion Risk: Managing governance and dependency debt when code moves at automated machine speed.
- 07:27 - Regulatory Pressures & The CRA: Preparing for 24-hour vulnerability reporting deadlines and mandatory SBOM provenance.
- 11:00 - Upstream Package Repository Economics: Addressing maintainer burnout and the influx of AI-generated PRs.
- 14:02 - The True Cost of Exposure: Mitigating enterprise risk across foundational open source language libraries.
- 16:27 - Rapid Fire Round: Tux the Penguin, favorite emojis, time travel, and key takeaways for the community.
Episode links:
What's in the SOSS? An OpenSSF Podcast med OpenSSF finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.