Skip to main content
Abby Kearns

Abby Kearns

Jul 20, 2026

7:36
So if my group's building an AI SDLC, kind of going further left to the pipeline than you traditionally would do with an AI-assisted environment, how are you fitting in over there then?
7:50
It's just replacing where you pull your packages from.
7:52
That's all.
7:53
It's like today, if you're using AI, any AI code generator, you're pulling packages directly from package managers.
8:00
If you look and pay close attention to what your cloud code or cursor or codex is pulling from, it's largely NPM, PyPy, Maven, wherever those packages are, or beyond those package managers, maybe some esoteric library that sits out there that doesn't even go through those package managers.
8:21
And so that's where a lot of the security and the vulnerability is being introduced, is there are no guardrails around any of that.
8:29
Basically, it is, for better or worse, it is the wild, wild west.
11:38
Do you have that in your roadmap?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.