Home / Companies / JFrog / Blog / Post Details
Content Deep Dive

Coding Agents Just Reopened Your Software Supply Chain Blind Spot

Blog post from JFrog

Post Details
Company
Date Published
Author
Yonatan Philip, JFrog Senior Product Manager
Word Count
1,095
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

AI coding agents such as Cursor and Claude Code can autonomously select and download dependencies from public registries, creating a software supply-chain governance gap because these downloads may bypass organizations’ controlled repositories, scanning, policies, and audit trails. The risk is heightened by growing malicious-package activity and “slopsquatting,” in which attackers register package names hallucinated by AI models. JFrog’s preview Agent Package Resolution feature aims to route agent-driven dependency requests through JFrog Artifactory, applying existing Curation policies, Xray vulnerability and license scanning, and logging without requiring developers to manually configure projects. Available initially for Claude Code and Cursor, it uses session steering, persistent package-manager configuration, and server-side policy enforcement to cover direct, indirect, and transitive installs. The company says the approach gives platform and security teams governance parity for AI-assisted development while allowing developers to retain their existing workflows.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.