ActiveState Artifact Repository – Loreli Cadapan, ActiveState
ActiveState releases ActiveState Artifact Repository to enable organizations to securely build Python dependencies directly from source code. Rather than developers importing prebuilt Python dependencies from a public repository like the Python Package Index (PyPI), or from some internal build process that may not be secured from supply chain attacks, all Python artifacts are created via ActiveState’s secure build service and stored directly in their own private ActiveState Artifact Repository for distribution, creating a closed-loop environment that maximizes supply chain security.
Transcript
This is texturing TV. everyone Thank you for joining us for another tech strong event. I am happy to have Lorelai katapan from active State here on textrug TV, and it's her first time on so let's welcome our hey Laura Lee.
How are you? Hey, Alan, I'm good. Good.
Thank you. So more like you have the honor of being I think the First Act of State person we've ever interviewed on Tech strong TV. So it kind of falls on your shoulders then to carry it tell our audience a little bit about active stay.
What's the company do? Absolutely. So Active Space state has been around actually for at least 20 years.
It's gone through various Journey have pivoted a couple times and now active state is in the open source securing or print Source supply chain and Where we're at is essentially solving the problem of and the Pains of dealing with open source dependencies and whether that's Python and PM and so forth and what we provide is for, you know, we provide the solutions for all software vendors to ensure that there's the software that they're building is secure from source to components artifacts binaries. And that's where we really are where we shine. We have a secure build service that allows you to input all of the your dependencies and then we build all of those dependencies from Source ensure.
They all build correctly. They build in a hermetic secure way and produce for you a reproducible runtime and all of the artifacts are have attestations and provide you the S bombs. So, you know, you may have heard developers they love using open source, but what they hate is having to deal with the dependency how deal with ensuring that there's no tampering on those dependencies that they're consuming for building their software and that's what active state does.
how timely I mean that's that's certainly a big a big issue today, you know, where When you have the majority of the code and a lot of these apps actually being open source components and those components themselves are not kind of mono lithic. They're they're made of yet other components exactly the artifacts scriplets and you know, what have you, you know, it gets messy really quickly right trying to figure out what the heck's really in there. That's great.
Hey Laura, like before we jump into latest news out of active State. I wanted to give people a little bit of your background because this is I mean, this is an area where you you've been involved in for a while. Yes, and so I'm a developer at heart and you know right out of college.
I was programmer developer software engineer wanted became an architect. and then eventually got into product where I really found my passion and specifically in the domain of devops and you know, I spent good chunk of my time in a couple startups and then moved on to Oracle where I was there for about 13 years, you know from Fusion apps to middleware and then found my way to Jay frog and you know, and really love the products that they make that you know, they sell and And that's where really I found my my passion and so spent some time at jfrog for four years before joining active state. So yeah, I'm really passionate about devops passionate about solving the pains that developers are dealing with day and day out as they build their software especially with the secure yourself for supply chain now being a friend and center and developers money to just code wanting to just code fast and be initially, you know Innovative and and so forth and now there's security having that they have to deal with and so my passion is to help them become a developer again and and become a security developer, so Cool.
All right. Let's Crystal thank you for that and thank you for the background on active State. Let's jump into the kind of the latest news from active State.
They recently had an announcement. I don't want to steal the story. It's your story.
Why don't you tell the folks about this latest Innovation? Absolutely. I'm so you know with the of course with the recent news from the executive order really putting down the hammer on securing all of the software that all user you US government agencies are consuming and using ensuring that they're attestations or during that they have s bomb in place.
And with active State now having had 20 years of experience in this space. We feel like it's finally come there. We feel that we were at least a couple years ahead of any other vendors out there in this providing those kind of solution.
There's also I don't know if you're familiar with salsa. So they provide it's essentially starts for supply chain levels for software artist artifacts. And so what they provide our Frameworks to and best practices to ensure the Integrity of artifacts specifically for any kind of artifacts including open source artifacts, and so Having both of those we've really positioned our solution and our value proposition around that and so what we do is essentially we turn, you know, open source from Source building from stores all the way to the binaries.
and that's that and so the recent releases that we've done, you know, we've we are now providing s-bombs software develop materials for all of the dependencies in your runtime. So what active state does is it provides you a runtime that has all of you the dependencies that you need to be able to run your software be able to develop your your software? And so and then soon after that we have now released the ability to have attestations for every single artifact that you're using or you're consuming for your software.
And so this is the biggest thing. We we believe that this is something that every software vendors, especially those that are providing Services providing software to the US government agencies or US government contractors are going to need and so we we're very excited about that that the recent release and we're going to continue to expand on that as the standards evolve, you know. So yeah, you know, it's interesting is and I've been through this right security company in the early 2000s.
So primarily 60 70% of our business was the odd. various other agencies and what was interesting is you see rather quickly that oftentimes the standards that the feds adopt that you know, the federal government adopts. Rather quickly becomes industry standard too right next after that.
Usually the financial industry says way SEC if they're doing it we should do it too. And then it's the healthcare industry. Now, you gotta Financial Health Care manufacturing and who's left, right?
So this does usually especially we see it happening with so forth Supply chains and that's bombs and all that. You know, we're seeing rapid. Awareness and and involvement across all Industries to say.
Hey, we got to know we got to know what's in here. Right so that we're not the next victim right? Yes, and I'm You know dealing with direct dependencies sure is a little bit challenging.
But then once you get into the transitive dependencies and all of the sea libraries that they depend on right the native libraries depending on the operating system that you're dealing with whether it's Linux Windows Macos. That's when it becomes really challenging to be able to build and ensure that all of the dependencies and transitive dependencies for your runtime is there and you know, they all play well special when you have a software with very large set of dependencies. That's when it can become a big Challenge and that's where you know where our customers are really seeing the value of the the platform is having this reproducible runtime being able to build all of their dependencies and then now having that at station as bomb in place such that they can trust the runtime the software that they're getting active state got it.
so I asked you this off camera. I might as well ask you on camera. Obviously J frog where you used to work against artifactory, right?
Probably one of the most famous. Almost widely used repos in the world strictly for artifacts. How does this compliment or compete or is it just two separate things?
It's really yes and it really does complement Jay frog artifactory in that. So what we provide is also the ability to create a private repository or artifact repository that contains only the dependencies that you need or the developers are that, you know, the things the components artifacts that you're developers should be consuming from And this could be vetted out by your abstract your CSO your see your security engineers. And so as you know artifactory can proxy if you will other remote repositories out there such as Pi Pi and PM Jay Center and so forth so we could become a vetted catalog a curated catalog with all of the dependencies and artifacts that because that the developers can then consume from so it's another remote repository that artifactory can proxy that will contain all of the dependencies that you have to build your software ensuring that there is attestation for each of those artifacts.
Excellent. Very cool. Hey, Laurel.
I for people who want to get information. How do you what do you recommend they do? So absolutely get on our website and you know, there is a free tier that you can sign up as a self-serve feature.
You can try it out and there is ability to try the s-bombs and attestations in place just sign up for a demo and then we will ensure that your subscription does have those features in place. io. What's the website?
com. Yes, actually, thank you Laura like so and there's a free tier too, man. What more can you ask for exactly?
There's the free tear Triad get your hands on the platform and you know, we'd love to to get the feedback from from developers from you know csos from App sex and definitely want to hear from them and and you know provide if there's any gaps definitely want to hear them and start working on them. So I want to emphasize though. This isn't just for government folks right anyone who's interested in software supply chain and the testations and and S bombs and so forth should should be looking at this.
That's right and attestations the whole security factors just one value proposition that we provide the other value proposition is again getting through dependency house, especially if you're building for across different operating system and The ability to really resolve your dependencies making sure that they build from Source. This is something that we provide the other value proposition. Is this reproducible runtime.
So for example, you know you may have new developers coming into the into your team and it takes them some time to set up their development environment. Well with active State platform it takes No time at all to be able to you know, spin up a runtime environment for your development and start coding away for and contributing to your software. Got it, great stuff.
Hey, Laurel. I want to thank you for being your guest on textjunk TV. Thank you.
The last time come on more back and keep us posted. Yes. Absolutely.
Thank you. And I really appreciate your time there. Not a problem.
We'll take a break. We'll be back in Tech strong in a moment.