Software Supply Chain AI Coding Agents Now Ship Software. Plugin4Shell Shows Nobody Checks the Package A zero-click plugin swap bypasses SHA pinning in four major AI coding agents. The fix has to ship in the agent itself, and updating is only the complete remedy where one exists.
Software Supply Chain SBOMs and the Evidence Gap in Software Supply-Chain Security An SBOM improves visibility into software components, but provenance and verification are separate controls.