@ActiveState

ActiveState enables DevOps, InfoSec, and Development teams to improve their security posture while simultaneously increasing productivity and innovation.

Vancouver, BC
Joined November 2008
If a CVE lands on your team today, can you answer “are we exposed” in minutes, not days? A governed source with a contractual SLA (5 business days for critical, clock starting at upstream fix availability) turns that into a scheduled event instead of a fire drill. Worth checking before you need the answer.
60
A flaw just landed on CISA’s Known Exploited Vulnerabilities catalog. The remediation clock started the day it was listed, not the day your team got around to checking. Could you answer “are we exposed” right now, in minutes? Most teams can’t. That’s not a scanning problem. Read the full article: buff.ly/IJinydh
1
115
319 of 639 packages carried it in May. 111 days dormant. Then it resurfaced in four new packages, straight past npm's own malware scanner. Same week: CVE remediation across 21 major vendors got slower, not faster. Link below for the full article
1
110
Famous last words right before production goes down on a Friday at 5PM 🙃
99
Anthropic, Google, and OpenAI's coding-agent tooling has critical flaws sitting in the permission and sandboxing code wrapped around it, not in the models themselves. Jonny Rivera on why the wrapper is the attack surface, not the agent: buff.ly/uUuJ1Om
1
1
91
Why did open source security stay an afterthought for so long? Our CEO Abby Kearns has an answer: 'It's a shortcut we were all happy to live with.' Via Alex Scroxton at @ComputerWeekly
1
68
Open source is in 98% of the software running today. Her read on why that finally matters: 'I'm hoping people are standing up and paying attention now, with just the pure number of attacks on the software supply chain that we've seen.'
1
18
AI-assisted engineering teams: 63% say their scope grew in the past year. 45% are working longer hours. Both numbers point to time spent maintaining code that's already shipped, not time spent writing it.
1
90
The fix: govern what comes in before it becomes next quarter's maintenance backlog, not slow AI down trying to catch up after the fact. Full breakdown in the reply below. Where does this show up first on your team: the roadmap, the backlog, or a Slack thread nobody's resolved yet?
1
11
Today, the EU Cyber Resilience Act's Article 14 obligations become enforceable. If you sell products with digital elements into the EU, you now have 24 hours to report an actively exploited vulnerability from the moment you know, even in products that shipped years ago. A scanner report sitting in a dashboard isn't a compliance answer. A defined, auditable process is. Non-compliance sits in the CRA's highest penalty tier: up to €15 million or 2.5% of global annual turnover, whichever is greater. December 2027 is the deadline everyone's watching. Today is the one that just quietly became real. Start closing the visibility gap now. Read the release: buff.ly/LV9lylc
2
64
Today is International Women in Cyber Day 🎉 At ActiveState, these 17 women are building, innovating, and driving our team forward every single day. To our team, partners, and community: Drop a comment below to tag and celebrate the ActiveState women who’ve made an impact on your work. 💙 #InternationalWomeninCyberDay
87
"Open source is really having a bit of an existential crisis," says Abby Kearns, ActiveState CEO, in a new @computerweekly interview. AI agents pulling packages, developers choosing convenience over scrutiny, governance treated as a compliance checkbox. The conversation has to change, from scan-and-alert to actually managing risk. Read the full piece: buff.ly/h04y022
76
Minimus is shutting down. The founders built Twistlock before this, and John Morello wrote NIST SP 800-190. A 60-day maintenance window and refunds for enterprise customers is a more graceful exit than most vendors manage. An open letter to their customers (a thread):
1
135
We surveyed 250 DevSecOps leaders: 83% named outdated base images as the root cause of their most recent vulnerabilities. 90% are still running lightly modified public images with little to no hardening. We wrote about this gap in June 2025.
1
17