Uploaded June 2026 | Updated September 2026, 22 hours ago
AI coding agents are accelerating development to unprecedented speeds, with top engineering organizations now delegating the majority of coding tasks to AI. But while AI-driven development unlocks new productivity, it also scales supply chain risk to machine speed: a single prompt can introduce dozens of new dependencies to your project, with agents pulling code from the same public registries hit by Shai-Hulud, the XZ backdoor, and recent attacks against Trivy, LiteLLM, and axios.
Join our May Learning Labs with Erika Heidi, Staff DevRel Engineer at Chainguard, to learn how to build AI-generated applications on a foundation you can trust, leveraging our partner Cursor and the Chainguard ecosystem for a hardened supply chain from development to production.
TIMESTAMPS
00:00 Introduction and agenda
03:35 "This Changes Everything"
04:19 How the threat model changed with AI
08:17 Your local dev environment at risk
09:49 AI-native attack vectors
12:30 Closing the trust gap
14:14 Two principles for a safe SLDC with AI assistance
23:06 Vibecoding with trusted sources
27:26 The Chainguard plugin for Cursor
29:03 Demo - building an SBOM visualizer
31:27 The initial prompt
33:50 The resulting vibecoded app
34:20 Migrating to Chainguard Libraries
36:43 Verifying coverage
38:26 Recap of what we neutralized
40:15 Other Chainguard skills to try out on Cursor
48:45 Wrapping Up
About Chainguard
Founded by the industry's leading experts on open source software, security and cloud native development, we are on a mission to be the safe source for open source.
Where to find us:
Website: https://www.chainguard.dev/
Twitter: twitter.com/chainguard_dev
LinkedIn: linkedin.com/company/chainguard-dev
TikTok: tiktok.com/@chainguard_dev
AI coding agents are accelerating development to unprecedented speeds, with top engineering organizations now delegating the majority of coding tasks to AI. But while AI-driven development unlocks new productivity, it also scales supply chain risk to machine speed: a single prompt can introduce dozens of new dependencies to your project, with agents pulling code from the same public registries hit by Shai-Hulud, the XZ backdoor, and recent attacks against Trivy, LiteLLM, and axios.
Join our May Learning Labs with Erika Heidi, Staff DevRel Engineer at Chainguard, to learn how to build AI-generated applications on a foundation you can trust, leveraging our partner Cursor and the Chainguard ecosystem for a hardened supply chain from development to production.
TIMESTAMPS
00:00 Introduction and agenda
03:35 "This Changes Everything"
04:19 How the threat model changed with AI
08:17 Your local dev environment at risk
09:49 AI-native attack vectors
12:30 Closing the trust gap
14:14 Two principles for a safe SLDC with AI assistance
23:06 Vibecoding with trusted sources
27:26 The Chainguard plugin for Cursor
29:03 Demo - building an SBOM visualizer
31:27 The initial prompt
33:50 The resulting vibecoded app
34:20 Migrating to Chainguard Libraries
36:43 Verifying coverage
38:26 Recap of what we neutralized
40:15 Other Chainguard skills to try out on Cursor
48:45 Wrapping Up
About Chainguard
Founded by the industry's leading experts on open source software, security and cloud native development, we are on a mission to be the safe source for open source.
Where to find us:
Website: https://www.chainguard.dev/
Twitter: twitter.com/chainguard_dev
LinkedIn: linkedin.com/company/chainguard-dev
TikTok: tiktok.com/@chainguard_dev










