# What's in the SOSS? Podcast #73 - S3E25 Securing the Source: Navigating AI Velocity, CRA Compliance, and Dependency Debt with Abby Kearns

DevFeed: [What's in the SOSS? Podcast #73 - S3E25 Securing the Source: Navigating AI Velocity, CRA Compliance, and Dependency Debt with Abby Kearns](<https://devfeed.tech/articles/what-s-in-the-soss-podcast-73-s3e25-securing-the-source-navigating-ai-velocity-cra-compliance-and-dependency-debt-with-abby-kearns-57848.md>)

Original publisher: [Read original article](<https://openssf.org/podcast/2026/09/22/whats-in-the-soss-podcast-73-s3e25-securing-the-source-navigating-ai-velocity-cra-compliance-and-dependency-debt-with-abby-kearns/>)

Author: OpenSSF

Published: 2026-09-22T14:40:40Z

Content type: article

Language: en

Sources: [Open Source Security Foundation](<https://devfeed.tech/sources/open-source-security-foundation.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Risk](<https://devfeed.tech/topics/risk.md>), [Repository](<https://devfeed.tech/topics/repository.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-vulnerability-management](<https://devfeed.tech/tags/ai-vulnerability-management.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cra-compliance](<https://devfeed.tech/tags/cra-compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [dependency-debt](<https://devfeed.tech/tags/dependency-debt.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

## AI overview

This podcast episode examines open source security, including the limits of reactive post-build scanning, risks from AI-driven code ingestion, dependency debt, maintainer pressure, and the implications of the EU Cyber Resilience Act for enterprise software supply chains.

## Source excerpt

In this episode of What's in the SOSS, ActiveState CEO Abby Kearns breaks down the rapidly evolving open source security landscape. The conversation explores why reactive post-build scanning fails, the risks of AI-driven code ingestion, and how impending EU CRA mandates will impact enterprise software supply chains.