What’s in the SOSS? Podcast #73 – S3E25 Securing the Source: Navigating AI Velocity, CRA Compliance, and Dependency Debt with Abby Kearns
AI Cybersecurity Classified by Officially
Summary
In this episode of What’s in the SOSS, host Sally Cooper sits down with technology executive and ActiveState CEO Abby Kearns to break down the rapidly evolving open source security landscape. Together, they dissect why reactive post-build scanning fails to prevent dependency debt, how machine-speed AI ingestion is overwhelming human maintainers, and what the impending EU Cyber Resilience Act (CRA) mandates mean for enterprise software supply chains. Abby offers actionable insights into why building a “start secure, stay secure” paradigm is essential for modern software pipelines and why open source communities must unite to redefine repository economics in an AI-dominated world.
Listen on Apple PodcastsListen on SpotifyListen on OvercastListen on Pocket CastsConversation Highlights
00:00 – Introduction: Sally Cooper welcomes ActiveState CEO Abby Kearns to discuss AI, vulnerability management, and open source security.
01:50 – The Limits of Reactive Scanning: Why controlling components at the build source beats post-build scanners.
04:39 – AI Agents and Ingestion Risk: Managing governance and dependency debt when code moves at automated machine speed.
07:55 – Regulatory Pressures & The CRA: Preparing for 24-hour vulnerability reporting deadlines and mandatory SBOM provenance.
11:17 – Upstream Package Repository Economics: Addressing maintainer burnout and the influx of AI-generated PRs.
14:03 – The True Cost of Exposure: Mitigating enterprise risk across foundational open source language libraries.
16:45 – Rapid Fire Round: Tux the Penguin, favorite emojis, time travel, and key takeaways for the community.
Episode Links
- Abby Kearns’ LinkedIn Page
- Active State Website
- EU Cyber Resilience Act (CRA) Overview
- Linux Foundation Projects
- Get involved with the OpenSSF
- Subscribe to the OpenSSF newsletter
- Follow the OpenSSF on LinkedIn
Transcript
This is an extract. The publication continues at the source.
Read the original at the source: https://openssf.org/podcast/2026/09/22/whats-in-the-soss-podcast-73-s3e25-securing-the-source-navigating-ai-velocity-cra-compliance-and-dependency-debt-with-abby-kearns/
Officially imported this from Open Source Security Foundation’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Open Source Security Foundation — imported from official source
- Official source
- https://openssf.org/feed/ RSS
- Imported
- September 22, 2026 15:00
- Versions
- 1 recorded
- Identity
https://openssf.org/?p=11845