Trusted Open Source Catalogs for AI and Developers
Techstrong TV Interviews
•
16m
A trusted open source catalog is now table stakes for AI agents and developers alike. Leslie Pascual, Field Engineering Manager for AI and Security Solutions at ActiveState, joins Alan Shimel on Techstrong TV. Furthermore, they walk through how a trusted open source catalog shifts security all the way left.
About Leslie Pascual
Leslie has spent more than 20 years in tech across engineering, architecture and leadership. In addition, she landed in cybersecurity while hardening enterprise healthcare applications. Consequently, she now advises ActiveState customers on AI and secure software supply chain work.
Inside the trusted open source catalog
ActiveState is closing on 30 years and still supports Perl and Tcl alongside modern stacks. As a result, the company covers the top nine open source ecosystems today and is expanding to twelve. Meanwhile, catalogs span Python, Java, JavaScript and even R for enterprise teams.
Leslie explains that scanners only compare packages to CVE metadata after the fact. Furthermore, ActiveState vets components before they enter the environment. Consequently, packages go through a cool down period, secure build, attestation and strong provenance.
Where AI agents plug in
Meanwhile, AI agents pull open source from anywhere they can find it. Therefore, ActiveState becomes the source of truth for tools like Claude and Cursor. In addition, the platform plugs into JFrog Artifactory, Sonatype and Cloudsmith so developers see no extra friction.
Leslie also confirms that continuous monitoring keeps catalogs current with patches and fixes. Furthermore, ActiveState provides SBOMs and attestations for every component it ships. As a result, an MCP server is on the roadmap to extend that intelligence into the CI CD pipeline. In addition, mirrored repositories let each customer expose the catalog inside their own Artifactory instance.
Explore more artificial intelligence coverage and the latest Techstrong TV interviews.
For more information please visit activestate.com
Up Next in Techstrong TV Interviews
-
AI Token Costs Fall While Enterprise ...
### AI Cost Management Moves Into Focus
AI token costs are falling, but enterprise AI spending is still rising. In this Techstrong AI Leadership Insights conversation, Mike Vizard talks with Jon Knisley, Director of AI Value Management at ABBYY, about why lower token prices do not always transla...
-
AI Is Collapsing the Vulnerability Pa...
### AI Vulnerability Management Gets More Urgent
AI vulnerability management is becoming a priority as attackers move faster after disclosure. In this Techstrong TV conversation, Mike Vizard talks with Andrew Obadiaru, CISO at Cobalt, about why the gap between vulnerability discovery and exploit...
-
Federal Cyber Hack-Back Plan Raises A...
### Federal Cyber Hack-Back Enters a New Phase
Federal cyber hack-back policy is moving into a more formal phase as government agencies explore deeper collaboration with private cybersecurity firms. In this Techstrong TV interview, Mike Vizard talks with Chris Nyhuis, President and CEO of Vigila...