Security Teams Are Fixing Vulnerabilities Faster Than Ever. So Why Is Software Getting Riskier?
AI is speeding up dependency decisions, making point-of-selection security essential for reducing vulnerable components, downstream tickets and avoidable rework.
Security teams have been making significant strides in fixing software vulnerabilities more rapidly in recent times. However, the increasing pace of software development and vulnerability discovery has led to growing concerns about the risk associated with applications. While the median age of unresolved critical and high vulnerabilities has decreased by 59% since January 2024, more than half of resolved violations are now addressed within a day.
Yet, software production and vulnerability discovery continue to escalate, necessitating a deeper examination of the initial software decision-making process.
AI-powered coding assistants and agents are rapidly changing the way developers make dependency decisions, compressing hundreds of component choices into shorter development cycles. This acceleration of decision-making comes with the risk of placing undue pressure on security controls, as vulnerabilities are only evaluated after they have been selected.
When a vulnerable dependency is chosen, a downstream scan is triggered, an alert or ticket is generated, and the developer is eventually prompted to reconsider the dependency. By then, valuable time may have been wasted on rework.
To address this issue, several changes are recommended. First, security intelligence should be brought closer to the decision-making point, providing developers and agents with current information about vulnerabilities, component health, and organizational policies. This will enable them to make more informed choices and reduce the number of rework tickets.
Second, agents should receive similar guardrails as developers, with organizational policies around approved components, risk, and licensing guiding their component decisions. As agents gain more autonomy, these guardrails should follow them. Third, automating the process of upgrading to safer dependencies is crucial, as it provides developers with a validated path forward and reduces the number of alerts they must investigate.
Finally, teams should measure the frequency of avoidable risks introduced into the pipeline. By tracking both the speed of vulnerability remediation and the introduction of preventable risks, development teams can identify areas for improvement and optimize their processes accordingly.
Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.