Coding Agents Just Reopened Your Software Supply Chain Blind Spot
jfrog.com | blog | #ai-security | #supply-chain | #npm | #jfrog | #ai-agents | #software-supply-chain | #slopsquatting | #artifactory
Summary
JFrog warns AI agents bypass governed supply chains by fetching dependencies from public registries, amid a 451% surge in malicious npm packages and slopsquatting risks. Its fix: Agent Package Resolution routes agent downloads through Artifactory so policies, scanning and audit trails apply again.
Why it matters
This coverage gives security teams current context for monitoring, validation, and remediation.
- Published
- Collected
Skip to content