ActiveState
14.7K posts

ActiveState
@ActiveState
ActiveState enables DevOps, InfoSec, and Development teams to improve their security posture while simultaneously increasing productivity and innovation.
Vancouver, BC Katılım Kasım 2008
1.6K Takip Edilen4K Takipçiler

Employee Spotlight: Brandy Coulsey, our Brand and Communications Manager, keeps ActiveState's story in front of the right people at the right time. Her one word for the last 6 months? Invigorating. Happy to have you on the team, Brandy!
#EmployeeSpotlight #TeamActiveState




English

The industry average time to remediate a critical CVE is upwards of 50+ days.
That's not a gap. It's a documented exposure window your auditors and insurers can measure.
Govern open source software at the point of ingestion so the clock never starts.
read more: buff.ly/FTv3qpb
#OpenSourceSecurity #SoftwareSupplyChain #CVE #CISO
English

Developers used to pick their own open source packages. Now Claude, Cursor, and Copilot pick for them. ActiveState CEO Abby Kearns on why that's rewritten the rules for the software supply chain, in FastForward: buff.ly/ffRMWb4 #SoftwareSupplyChain
English

Let's talk about the EU Cyber Resilience Act for a second. Your boss might say you've got runway. Your gut might say otherwise.
Real prep starts with visibility: knowing what open source software and packages are running in your stack, having SBOMs on hand, and a plan for managing vulnerabilities as they come up.
With ActiveState, you really do have runway. Talk with our team to learn how.
#CyberResilienceAct #EUCRA #OpenSource #AppSec #SoftwareSupplyChain
English

FedRAMP auditors do not ask if you scanned. They ask where the software came from. Scan and pray does not answer that question.
#OpenSourceSoftwareSecurity
English

@otnoxcom Exactly this. "Free" was never the same as "no obligations" and CRA formalizes what should've been true all along: every component gets an owner, evidence of what's in it, and a lifecycle someone is accountable for
English

@ActiveState Exactly. OSS skipped procurement because it felt “free,” but obligations don’t care about price. CRA will force companies to treat components like suppliers: owner, evidence, review, and lifecycle control.
English

Open source software is the largest liability most companies never put through a process. No procurement, no review, no signature. The obligation did not vanish. It compounded off the books, and the EU CRA clock starts September 2026.
buff.ly/L7y8luk
#SoftwareSupplyChain
English

“We had a scanner” is not a defensible decision. It describes a tool. After an incident, the question is who decided this component was allowed in, on what basis, and can you produce the record.
buff.ly/L7y8luk
#CISOAccountability #SoftwareSupplyChain
English

The fix isn't a better meeting between security and engineering. It's governing open source at the point of ingestion, so the dependency an AI suggests is already vetted before it ships.
#OpenSourceSoftwareSecurity
English

Renaming your security program "cyber resilience" doesn't make it resilient.
If you still find vulnerable open source software with a scanner after it's in your build, you rebranded the backlog. You didn't fix it.
Resilience starts at ingestion, not incident response.
read more: buff.ly/FTv3qpb
#CyberResilience #OpenSourceSecurity #SoftwareSupplyChain #DevSecOps
English
ActiveState retweetledi

Your developers work across 20+ languages. Does your governance?
Developers routinely work across more than 20 programming languages, each mapping to at least one package ecosystem, per the IDC Analyst Brief sponsored by @ActiveState. That is a software supply chain footprint too complex to govern reactively. See where the gaps form.
Download the Brief: thn.news/securing-open-…

English
ActiveState retweetledi

🟢 A green CI pipeline doesn't always mean it's secure.
🛡️ @ActiveState explains why GitHub Actions attack chains can remain exploitable despite passing CI security scans.
➡️ bleepingcomputer.com/news/security/…
#cybersecurity #sponsored

English

Grateful to be named Best Open Source Security Platform by The Hacker News Cybersecurity Stars Awards 2026.
The Open Source Security category recognizes companies demonstrating excellence in defending the software supply chain. The ActiveState Curated Catalog earned it for governing open source software at the point of ingestion, where AI coding assistants pull dependencies in a single keystroke with no provenance check.
Scan and pray cannot keep pace. Curate and govern can.
Thank you to The Hacker News for this recognition.
Read the announcement: buff.ly/yEyO5MU
#OpenSourceSecurity #SoftwareSupplyChain #Cybersecurity

English

Security holds the line on risk. Engineering holds the line on the roadmap. Neither team chose the open source dependency that started the argument. AI did.
#SoftwareSupplyChain
English

Gartner published its Magic Quadrant for Software Supply Chain Security.
🔹ActiveState has been named a Niche Player.🔹
We govern open source at the point of ingestion: built from source, SLSA Level 3, contractual remediation SLAs.
Read the release: buff.ly/6eB2Ea8

English

@kaikuro_iso Quick version: it's a tamper-proof receipt for your code, proof of where it came from and how it got built, that nobody can secretly edit later. Coffee first, provenance later. ☕️
English

@ActiveState i literally do not know what immutable provenance means but it sounds sooo intense honestly good luck with all the code stuff im just gonna drink my late night coffee now ☕️💫
English

"The governance gap is not a resourcing problem. It's an architectural mismatch between how security tools were built and how code is actually being written today."
Built-from-source. Immutable provenance. Managed remediation SLAs. These aren't best practices. They're requirements.
buff.ly/CN6bylV #SoftwareSupplyChain #CISO #DevSecOps
English

The EU CRA just turned your SBOM from a best practice into a product requirement with a date on it. A document you skip is a gap. One you are required to produce and cannot is a finding with your name on it.
buff.ly/yRMeTZP
English