What’s in the SOSS? Podcast #73 – S3E25 Securing the Source: Navigating AI Velocity, CRA Compliance, and Dependency Debt with Abby Kearns

Imported from official source

AI Cybersecurity Classified by Officially

Summary

In this episode of What’s in the SOSS, host Sally Cooper sits down with technology executive and ActiveState CEO Abby Kearns to break down the rapidly evolving open source security landscape. Together, they dissect why reactive post-build scanning fails to prevent dependency debt, how machine-speed AI ingestion is overwhelming human maintainers, and what the impending EU Cyber Resilience Act (CRA) mandates mean for enterprise software supply chains. Abby offers actionable insights into why building a “start secure, stay secure” paradigm is essential for modern software pipelines and why open source communities must unite to redefine repository economics in an AI-dominated world.

Listen on Apple PodcastsListen on SpotifyListen on OvercastListen on Pocket Casts

Conversation Highlights

00:00 – Introduction: Sally Cooper welcomes ActiveState CEO Abby Kearns to discuss AI, vulnerability management, and open source security.
01:50 – The Limits of Reactive Scanning: Why controlling components at the build source beats post-build scanners.
04:39 – AI Agents and Ingestion Risk: Managing governance and dependency debt when code moves at automated machine speed.
07:55 – Regulatory Pressures & The CRA: Preparing for 24-hour vulnerability reporting deadlines and mandatory SBOM provenance.
11:17 – Upstream Package Repository Economics: Addressing maintainer burnout and the influx of AI-generated PRs.
14:03 – The True Cost of Exposure: Mitigating enterprise risk across foundational open source language libraries.
16:45 – Rapid Fire Round: Tux the Penguin, favorite emojis, time travel, and key takeaways for the community.

Episode Links

Transcript

This is an extract. The publication continues at the source.

Read the original at the source: https://openssf.org/podcast/2026/09/22/whats-in-the-soss-podcast-73-s3e25-securing-the-source-navigating-ai-velocity-cra-compliance-and-dependency-debt-with-abby-kearns/

Officially imported this from Open Source Security Foundation’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Open Source Security Foundation — imported from official source
Official source
https://openssf.org/feed/ RSS
Imported
September 22, 2026 15:00
Versions
1 recorded
Identity
https://openssf.org/?p=11845

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.