Registry-to-runtime handoff for securing AI-driven supply chains
AI agents add dependencies to builds faster than anyone can review them. Cloudsmith and Aikido Security's product leaders take one package request and show you which controls can help keep malicious packages out of your builds – at the registry, and at runtime.
Things you'll learn
- Block a package before it's installed: Write registry policies that evaluate an agent's package request and block, flag, or conditionally allow it.
- Use SBOMs as an enforcement gate: Check SBOM contents against policy at build time and fail the build on a violation, instead of filing the SBOM for audit.
- Reduce container scan findings: How reachability analysis separates vulnerabilities your code can reach from those it can't, and how provenance data from the registry narrows the remaining list further.
- Connect the two layers: Decide which signals your registry should pass to detection, and which detection findings should tighten policy.
Speakers


Summary
AI coding agents now install open source dependencies without a person reviewing each package they pull. Every install is a trust decision, and review processes built around a developer at a keyboard no longer cover them. Strict supply chain governance requires controls that run automatically where a package is requested, installed and executed.
Alison Sickelka, VP of Product at Cloudsmith, and Mackenzie Jackson, Field CTO at Aikido Security, follow one package request from request to production so you can see which checks belong where. Alison starts at the registry, where policy blocks, flags or conditionally allows the package. Mackenzie picks it up on the assumption it passed those checks, and shows what Aikido Security detects on the developer machine, in CI, and at runtime.
The two end on the handoff: which signals a registry can pass to downstream detection, and which detection signals can return to policy. You should leave able to name the control points you have, the ones you're missing, and how each keep you more secure. Live Q&A at the end.