Session
From Alert to Fix: How AI Agents Are Changing Dependency Remediation
When the Axios npm package was poisoned in March 2026 reaching 100 million downloads per week teams with automated dependency remediation closed their exposure window in hours. Teams without it spent days manually triaging alerts.
Dependency vulnerabilities don't wait for human review cycles. But traditional security tooling still treats remediation as a manual, linear process: alert fires → engineer reads it → engineer opens a PR → engineer merges it. That loop is too slow when attacks cascade across five package ecosystems in two weeks, as the TeamPCP campaign demonstrated this year.
This session breaks down how AI agents are collapsing that loop. Drawing on the architecture of AI-assisted dependency remediation at scale across 20+ package ecosystems and hundreds of millions of repositories, I'll cover:
• How AI agents triage dependency alerts, separating exploitable vulnerabilities from noise
• How agents handle the hard cases: breaking changes, transitive dependencies, and packages with no safe upstream patch
• The attack surface AI introduces when remediation automation itself becomes a target, as prt-scan's 500+ malicious PRs against GitHub repositories demonstrated
• What "autonomous remediation" actually looks like in production: the guardrails, failure modes, and human-in-the-loop design decisions that matter
Attendees leave with a concrete mental model for where AI accelerates dependency security, where it still needs a human, and how to build pipelines that don't trade speed for correctness.
Ankit Kumar Honey
Engineering leader securing the world's software supply chain at GitHub (Microsoft). MS Data Science candidate at Harvard. Building AI-driven defences for 180M+ developers.
Seattle, Washington, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top