ActiveState

14.6K posts

ActiveState banner
ActiveState

ActiveState

@ActiveState

ActiveState enables DevOps, InfoSec, and Development teams to improve their security posture while simultaneously increasing productivity and innovation.

Vancouver, BC Katılım Kasım 2008
1.6K Takip Edilen4K Takipçiler
ActiveState
ActiveState@ActiveState·
AI-generated code doesn't just accelerate development. It accelerates the inherited trust problem. Every import statement an AI coding tool generates is a potential new open source dependency. At 500-1,000 developers, that intake rate isn't human-scale anymore. The governance model most teams are running was never built for this. The road ahead requires a different kind of decision. Read more at buff.ly/Cf6bswN #softwaresupplychain #opensourcesecurity #AppSec #AIcode #CISOnotes
English
1
0
0
45
ActiveState
ActiveState@ActiveState·
Different generations, same source for trusted open source.
ActiveState tweet media
English
0
0
0
23
ActiveState
ActiveState@ActiveState·
'We were running a scanner' is not an audit trail for your OSS. SEC breach notification rules and the EU Cyber Resilience Act require documented, verifiable due diligence over your software supply chain. The question regulators will ask isn't whether you had tools. It's whether you made decisions. Most orgs cannot answer that question on demand today. Read more at buff.ly/Cf6bswN #CyberResilienceAct #softwaresupplychain #opensourcesoftwaresecurity #CISOnotes #compliance
English
0
0
0
35
ActiveState
ActiveState@ActiveState·
Everyone is asking whether their AI agents will do the wrong thing. Nobody is asking what happens if they were built on the wrong thing. That's the conversation missing from every governance framework, every session agenda, every vendor pitch right now. Underneath every agent in your environment is a software stack. Inside that stack: open source dependencies pulled in by AI coding assistants, accepted in a single keystroke, with no provenance check, no manual review, no assigned owner. Behavioral trust is a real problem worth solving. Can the agent do what I asked? Yes. But that question rests on a foundation most organizations have never looked at. Security doesn't start with what your agent does. It starts with what it was built on. #CyberSecurity #AIAgents #SoftwareSupplyChain
English
0
0
0
47
ActiveState
ActiveState@ActiveState·
CISOs: AI coding assistants don't just generate code. They generate open source risk. At machine speed. The fix can't be tethered to a single AI tool. It has to be at the dependency layer. That's exactly what the ActiveState Curated Catalog does. And today we expanded it to cover any AI coding environment. buff.ly/u1Sgjy0
English
0
0
0
42
ActiveState
ActiveState@ActiveState·
ActiveState has sponsored the latest IDC Analyst Brief on open source software governance at scale. What the IDC Analyst Brief found: curated open source catalogs are the only governance model that intervenes at the point where the problem actually starts. Learn more here: buff.ly/MhIARTY
English
0
0
0
28
ActiveState
ActiveState@ActiveState·
Two Apache ActiveMQ CVEs are now being chained for unauthenticated remote code execution. One is already in CISA KEV. ActiveState's Jonny Rivera on why this one stings: most organizations don't know they're running ActiveMQ at all. It's buried in transitive dependencies, untracked, and nowhere near the patch queue. You cannot patch what you cannot see. Patch target: 5.19.4 or 6.2.3. Read more at buff.ly/xEvq0hy #SoftwareSupplyChain #OpenSourceSecurity #CVE #DevSecOps
English
0
0
0
38
ActiveState
ActiveState@ActiveState·
The most important number in your security program right now is not your CVE count. It is how long your remediation sequence takes from "critical CVE identified" to "clean deployment in production." Most teams do not know that number. Project Glasswing is going to surface it for them. Full read: buff.ly/EjYfOTB #OpenSourceSecurity #CyberSecurity #AppSec
ActiveState tweet media
English
0
0
0
44
ActiveState
ActiveState@ActiveState·
Speed is a competitive advantage, and security is a requirement. 🛡️💻 As GenAI scales, shadow AI is becoming a massive risk to proprietary IP. Private repositories are now the gold standard for securing the AI driven development boom. Insights via @AppDevMag: ✅ IP Sovereignty ✅ AI Governance ✅ Risk Mitigation Read more: buff.ly/em8XVXm #GenAI #CyberSecurity #DevSecOps #TechLeadership
English
0
0
0
17
ActiveState
ActiveState@ActiveState·
RSAC 2026 made one thing clear: Security teams are hitting a wall. Faster reaction is no longer the answer. Here are the 4 key takeaways from ActiveState: Reactive security has peaked. CVE triage is exhausting teams. We need cleaner foundations, not faster patches. Visibility is the biggest hurdle. Many teams still don't know where their open source lives. You can't secure what you can't see. AI is outdistancing its supply chain. Rapid AI adoption is leaving the underlying open source libraries unexamined and at risk. Curation is the new prevention. Shifting to a verified base of packages stops the firefighting before it starts. The goal for 2026: Reduce the number of things that require a response in the first place. Read the full report here: buff.ly/tmo7nyb #RSAC2026 #CyberSecurity #OpenSource
ActiveState tweet media
English
1
0
0
36