About This Session
When an agent chooses your dependencies and assembles your build, answering what you are actually shipping gets genuinely hard. This talk starts with the fundamentals that make it answerable, including SBOMs, exploitability data, and build provenance, and shows how to apply them so an agent-assembled stack is one you can defend in a security review.
Topics
- AI Coding Assistants
- Compliance
- DevSecOps
- SBOM
- Security