The Safety Interviews: Abby Kearns, ActiveState
For over 15 years, as her profession took her from erstwhile digital transformation platform supplier Pivotal to the Cloud Foundry Basis, to configuration administration specialist Puppet and now ActiveState, the “by way of line” has been open supply, says Abby Kearns.
Kearns joined ActiveState as CEO again in March 2026. Her arrival on the Vancouver, Canada-headquartered firm coincided with a pivotal – no pun meant – second within the historical past of open supply software program, the appearance and affect of synthetic intelligence (AI) and snappily named tendencies similar to “vibe coding”.
“Open supply is vital to me – personally I feel it’s vital to everybody – as a result of it’s in actually the whole lot we do,” she says.
“The chance to come back again to open supply at a time when [it] is admittedly having a little bit of an existential disaster actually resonated with me, and the power to assist organisations proceed to put in writing nice software program, even when it’s AI co-generated, however accomplish that securely, was too good to go up.”
ActiveState has been round for the reason that late Nineteen Nineties, however has flown below the radar till comparatively lately, says Kearns.
“ActiveState actually began its journey serving to corporations determine find out how to handle end-of-life languages,” she says. “A variety of the early stuff was round Perl and Tcl. Even 30 years in the past, Perl was nonetheless not actively maintained, however organisations discovered it to be a important a part of their infrastructure and wanted an organization to assist them hold updated and handle it. That’s the place ActiveState started.”
Lately, the corporate claims to assist greater than 40 million open supply libraries by way of its Curated Catalog service, which serves as a trusted supply of well-maintained, safe open supply libraries for buyer developer groups to attract on.
‘Some random individual in Nebraska’
It could not have been considered a lot up to now, however the skill for organisations to have belief in open supply libraries has all the time been extremely vital, and it’s now turning into urgently so.
As any cyber professional with an curiosity on this discipline will inform you, it seems that open supply libraries are ripe for exploitation by menace actors for a similar purpose that they’re so standard with builders; they’re finally not managed by anyone organisation, however open to all, and because the well-known XKCD webcomic aptly and succinctly places it, typically thanklessly maintained for many years by “some random individual in Nebraska” who could not all the time have the capability to watch each change being made, or to resist a social engineering try. “It’s an excellent joke, but it surely’s a joke as a result of it’s true,” says Kearns.
Moreover, as we at the moment are seeing, AI is quickly heightening these dangers.
Certainly, not lengthy after Kearns’ dialog with Pc Weekly, AI fashions run by OpenAI tried to conduct a number of provide chain assaults of its personal by interfering with open supply libraries. In a single occasion, the Mythos agent concerned tried to arrange faux e mail accounts to commit a malicious bundle to its goal undertaking. In one other check run by the UK’s AI Safety Institute (AISI), it tried its hand at real-world social engineering.
However much less dramatically, and extra continuously, these points come up as a result of builders now not simply pull packages, they leverage AI assistants as a part of their growth workflows, and out of their “innate” want to look useful, the AI bots pull something they’ll to get the job performed, with out caring if it’s a manipulated bundle replace.
How did we get thus far? Kearns reckons an enormous change in attitudes happened slightly over a decade in the past, at in regards to the time the primary commit of Kubernetes was revealed to GitHub. She credit the following explosion in cloud-native providers with making organisations extra snug with consuming open supply packages straight from the faucet, with no intermediate software program supplier concerned.
Safety an afterthought through the gold rush
Sadly, safety – as is all too typically the case – was one thing of an afterthought throughout this gold rush. “It’s a shortcut we have been all glad to reside with,” displays Kearns.
All of which is to say no person actually had time for his or her hard-working developer groups to concentrate to safety; nothing unhealthy appeared to be taking place, so builders have been glad to drag from helpful libraries and safety groups have been glad to allow them to. And on the time, that wasn’t essentially a nasty resolution.
“By-and-large, open supply is often higher, it’s often safer, there are often extra eyes on it,” says Kearns. “It’s the proper selection.
“However now, it’s turn into an more and more prevalent approach to assault the software program provide chain. Open supply is a superb central level if you wish to have a whole lot of affect shortly, and [as such] it’s turn into an assault vector for folks with malicious intent which can be making an attempt to inject malware extra simply throughout a broader variety of victims.”
Because of these converging tendencies, says Kearns, she generally likes to assume that ActiveState’s founders could have been effectively forward of their time in some methods.
“Hastily, the market is rising to satisfy us – information is coming in every day now that [shows] that is actually the time to consider securing open supply,” she says. “Open supply software program is in 98% of all issues developed at present, and so is the underpinning of the whole lot.
“I’m hoping individuals are standing up and paying consideration now, with simply the pure variety of assaults on the software program provide chain that we’ve seen, and the rampant improve of these, and the implications of these will increase,” she says. “It’s blowing my thoughts every day.”
“I’m hoping individuals are standing up and paying consideration now, with simply the pure variety of assaults on the software program provide chain that we’ve seen, and the rampant improve of these, and the implications of these will increase. It’s blowing my thoughts every day”
Abby Kearns, ActiveState
Requested what cyber safety leaders and builders have to do to get forward of this downside, Kearns says there isn’t a actual guidelines, per se, past what has already been written a thousand instances within the IT commerce media – pay attention to what’s coming into your surroundings.
“I don’t essentially wish to say you must go tremendous deep in your SBOMs [software bills of material], however in case you are conscious of the open supply that you just’ve used and the packages that you just’ve pulled in, then you will have the chance to use governance extra rigorously,” she says.
“At a excessive stage, that’s what we inform our prospects, and that was the entire objective behind us constructing Curated Catalog, to offer prospects a repository of dependencies they’ll pull from which can be identified safe,” provides Kearns.
For a developer backed by such a product, her pitch is that nothing ought to basically change.
“They pull the code, it goes into their present repo of selection, they pull it into their present CI/CD [continuous integration and continuous delivery] pipeline – it’s no completely different from their standpoint,” says Kearns. “It mainly allows them to say, ‘right here’s a repo the place we’ve positioned the languages within the libraries you want, however they’re identified safe, so we will minimise our danger from upstream assaults’.”
Altering the dialog
Finally, Kearns says she needs to change the thrust of the narrative round open supply safety, shifting from one which centres SBOMs and compliance to 1 that centres a extra proactive strategy to the issue.
“That is much less about compliance adherence and extra about what is admittedly going that can assist you mitigate and handle danger in your organisation, as a result of there’s zero approach to apply sufficient people to this to navigate this – it’s shifting a lot too quick,” she says.
“All of us do compliance as a result of we’ve to, however no person goes, ‘yay, compliance makes me safer’. We actually wish to inform those that ‘that is vital, and right here’s why’. Now’s the time to have a extremely significant dialogue about it.”

