Loreli Cadapan, ActiveState | RSA Conference 2023
Loreli has 20+ years of experience in the enterprise software industry, successfully having worked at enterprise and startups, focused in DevOps and DevSecOps. She has held different roles from coding, architecture, development management, to product management. Loreli currently leads the product team at ActiveState, building products to power the world’s software development teams and accelerate their application security solutions.
Transcript
This is texturung TV. Hey, welcome to rsac 2023. We're in in San Francisco, of course back at the conference and doing some great interviews great conversations on Monday first day and have a great pleasure of being joined by Lorelei catapan.
Who is actually we know each other. We just did an event here recently talking about software supply chain Securities. So welcome.
Thank you here pleasure what introduce yourself and tell folks a little bit about active State. Okay, and so I'm VP of product at active State. I live in brief devops and devops.
It's what I am very interested in and so it active say we build technology that just works for developers focus on developers and Abstract leaders that allows developers to be able to because soon and use trusted open source so that they can focus on Innovation and you know, We build basically open source dependencies for you from source using a trusted reproducible hermetic environment and providing the S bombs and Providence attestations, which is now starting to surface up because of the executive order mandate and so forth. So yes, there are some candidate mandates that we all have to pay attention to even if we're not directly servicing, right, you know providing services to the government usually are to somebody who is exactly the chain of the chain of providing right secure software. So so talk a little bit more because I really like the approach that you're taking about.
It isn't just okay, like certifying that these are acceptable repositories or images or whatever you actually take a lot more steps to right right an environment that that's provided to people in as well as making sure open source components are safe. Right? Well we I mean, we know that developers Love Open Source, right, but It's a pain to build from Source because of the dependencies and dependency how all the way down to, you know, your native libraries and so active State, you know came with that vision of allowing developers to really focus on Innovation by just providing them the dependencies and so it's really shifting left more left than what you would consider SCA software composition.
I love analysis tool allowing developers to be able to pull their dependencies from a trusted catalog. For example that's vetted out and been built for you and providing the capability to build the dependencies regardless of how many dependencies that you have can be very complex. And so we make that easy for our developers to be able to build secure software.
You actually are before become exactly exactly and thought about That way. Yeah, you're you're come from a development background. I do.
Yeah, you were how long were you developer? I would have I would say 10 about 10 years as a developer right and focused believe it or not. I did some Pearl and then Mouton to CC plus plus and then Java before I got into product management.
So that's awesome. No, we're Gary background build from right have that experience and you know the life of you know, managing software and dependencies and doing updates on software. That's not yours it open source.
Right right and it can be super complicated especially if you're building something across different operating system for example, which is another I think Secret Sauce of our platform is being able to build your dependencies across multiple platforms, whether it's Linux Microsoft Windows or Mac for example and different languages. In different languages, we currently support python Ruby, of course Pearl and tickle. Yeah nice.
He had me at python. So that's my favorite environment. But and we're seeing a lot of python developers using data science, for example, so I think that's where we're starting to pick up on and really enhance our catalog with those libraries cool.
Cool. Now you're you're one of the Premier sponsors of devops connect devsecops that Tech drawing is hosting over in mosconee South 308 head over there if you're not over there already. Yeah, tell us about yeah exactly.
Tell us a little bit about you know, why that invent that event fits you really well in that audience. Yeah. So, you know, our platform really is about securing your application securing your software and we believe we're part of that picture.
We're part of that story, you know, you're there are many different. testing that you do before you actually ship out your software, you know, and that goes all the way from developer all the way to actually doing containerization testing application testing, but we're at the very First part of your software development life cycle where you're really understanding what dependencies that you have before you actually ship it and we hope to empower developers that way and eventually, you know, really be able to increase their development cycle and so forth. And that's I mean you talk about shifting life.
It isn't Shifting the burden the work to the developer matter of fact the more you can make it a non-work activity. Like I know it's Source from this this company this location this repository. It's already been checked out exactly that's just work developer doesn't have to do that's right.
That's easy thing to get some work done is not to have to do it right most productive. Exactly. And we really Empower developers by providing that curated catalogous dependencies that's been built and produce in a way that follows a lot of for example, then this secure software development framework.
And in fact, you might be familiar with salsa, you know under the ossf stands for supply chain levels of software artifacts. Yeah, and you got it exactly Right is a bit of a mouthful. Yes.
It's very much of a mouthful and it's still evolving. 0 and it's a framework and I believe that active states have had have been on that tenant since 20 years ago. I've really how do you build a build engine or framework or service that prevents, you know, man in the middle attack around your build processes, so You know, it's really validated what we're trying to do and what the problems that we're solving for Developers.
Great. I know you've had some renouncement recently. Tell us a little bit about kind of what's new and what people can take advantage of yes.
I'm so OMB memorandum since last year, you know, there's now defining who what when in terms of you know, what the government agencies need to do for when they're consuming their software and using software from their vendors. So we built some capabilities to be able to be compliant around that and being the Safe Harbor and so there's the s bomb which we've been we've had for quite some time now and now we're introducing Providence attestation based on the intodo framework using the salsa framework as well. So we are doing an early access program for that.
We want to get some feedback from our users our developers and so that we can continue to enhance that and continue to solve the problem and the pain points around that area. com and sign up on our Early Access program for that. And then there's also following that is the containerization being able to deploy your runtime environment The Trusted front-time environment built by the platform via a container stock or images specifically, so we're looking to get some feedback around that how do you know?
How do you how do you want it from a Docker image perspective is a digitalist. You want a local container registry and so forth. So want to get more feedback around that area as well.
So are you actually then building the containers based on what the elements are that exactly the developer once in their doctor exactly. So from you know them specifying the base image and then building the container with the open source dependencies that you need in order to deploy your software. Just think about the attestation the verification of having that record the kind of chain of custom you custody about how they got created.
Yeah, that's all part of that not having to me work when it comes to providing the attestation or information or verification of you know, it's no guesswork. We know exactly what happened. That's right.
And you know, there's so many many tools out there also to produce as bomb produce your Providence attestation, but a lot of those are on your proprietary code. Well, we provide is the ability to do the same exact thing but only but on your open source dependencies because we do build it from source and we can provide that full end-to-end Providence attestation as well as your VSA at a station. You really do know what it what's in that open source because it's usually just one project number of different sources of Open Source exactly is Turtles all the way down.
Right so building your direct dependencies all the way down to transitive dependencies down to the native Library such as your C libraries and so forth. So we build everything that make up your binary from Source. I'm curious when when developer uses active state.
Is there sort of an aha moment. Is there a point where they start to use the technology and go? Oh, okay.
This is actually really helpful or I get what this will do for me. Yes that experience like so a couple of things where we see the aha moment one is when they realize Oh, I have a reproducible environment now, right? So for example, you've got a developer coming into the to the team they need to set up their environment with all of the dependencies and so forth before they can start hitting the ground running.
Well, guess what instead of spending two three weeks setting up your environment now, we've got the runtime environment for you. That's reproducible and you can continue to enhance it and allow for collaboration between among the team members and then there's some audit Trail in their history. So, you know, it's we've married their solution with get as a model so that you can go back in time and and see okay who added this dependency and so forth.
So we have a lot of that mechanism in place already. So that's one and the other one is being able to not have to Kind of had that leap of faith of the you know, pulling your dependencies from a public repository. But oh wow, there's actually a solution out there a platform where I can pull down my dependencies.
I know it's vetted. I know it's been built. There's no attack that vectors from a build perspective that can happen.
So they've they can see that and so our security leads are starting to take notice of that as well and providing again the audit Trail and the software out of stations around it. So I think that's the other aha moment. I guess I'll add the third one, which is really about Being able to from a developer's perspective the you know, building your dependencies across the different stack or different operating system and you know every software out there is gonna be composed of different languages and so forth and we support that multi-language multi-operating systems.
It seems like it's one more thing that they can say now. I can check that off for the security team or the audit organization or I got my open source. Nailed down know what it works from what's in it right how to you know address it if we have an issue, but we know we're getting it from a trusted source.
So it's done that work for us. Yeah curious. So when you turn our attention to Not our first time at RSA right things have changed we've gone through some some years where we didn't get together for a little while.
What kind of started that backup last June? I guess it was and this year feels a little closer back to kind of Full Force RSA you have that sense too. I do I do, you know since the pandemic and special but now it's finally looking like normal, you know, and it's great to be able to talk to different stakeholders different roles different titles and so forth and being out there again in person, so I love it.
It's interesting too that we've kind of been anticipating that software being part of the conversation of security at RSA where it's been works very traditional and network security focus on all the elements of that but it is very much software and software development and application security very much part of the conversation now now with a lot of different companies. Yeah, I mean almost every company is building software, right and I think you know making sure that they're secure regardless of whether it's an internal software external especially at the Enterprise level is becoming top of mind and secure software supply chain is definitely I've seen a lot even in this conference already great. Well, hope you have a fantastic conference and a great.
Devops connect devsecops day. Thank you. I really appreciate it.
Good to see you finally in person. Is it is so nice like Oh, what now? I feel like I do really know you yes.
I know you. From our Zoom connection, but it's nice to meet in person. So more like thank you Lord, like catapan who is VP of product with active State be sure and check out their website your developer.
They've got a lot of things that you can jump right into and see how it works and test drive it kind of Kick the tires yourself. And of course if you're here at RSA, there's still you know, better part of a half a day left of devops connect. It's in room 308 on masconi South musconi South and active States one of the key sponsors there.
So thank you for sponsoring it and appreciate that. We'll be back. We said we had great guests.
Here you go. We're at we're delivering's we will see you back here at RSA in just a few minutes. com Security Boulevard Etc.
We'll be back in a few.





