Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
AI coding assistants are accelerating development, but they are also introducing unvetted or hallucinated dependencies that can lead to slopsquatting and supply-chain compromise. The article argues that enterprises must govern package selection before code reaches the build stage, with ActiveState positioning its curated catalog as a way to block risky dependencies at intake. #ActiveState #PyPI #npm #react-codeshift

Keypoints

  • AI-generated dependency suggestions can create supply-chain risk before code is even built.
  • Slopsquatting happens when attackers register hallucinated package names on PyPI or npm.
  • Researchers observed the npm package react-codeshift spreading through AI-generated agent skills and repositories.
  • Open source maintainers face more pressure as AI-assisted pull requests increase review burden and defects.
  • Enterprises need ingestion controls, curated catalogs, and pre-vetted packages to secure the pipeline.

Read More: https://www.bleepingcomputer.com/news/security/who-vets-ais-code-the-scale-challenge-facing-open-source-ingestion/