Feig: Open-source supply chain attacks will surge as AI agents flood pull requests
Gil Feig · "We Don't Trust Agents" - What This CTO Knows That You Don't · Sourcery with Molly O'Shea · Jun 1, 2026 · at 15:24
Merge CTO Gil Feig discusses growing AI security threats and how autonomous agents generate code changes faster than open-source maintainers can review.
“Agents are pushing a ton of code. You don't have enough humans to read all that code, and so things are slipping by, things are getting in, and one of them was a vulnerability that gets injected into an open source package that everybody relies on and uses, and so all of a sudden, that, that little, you know, virus or that file goes into all the code bases, and people are just getting really screwed over by that, so I think there is a need for seriously, like, slowing down, especially with these core packages, being incredibly careful Yeah, I think that's one of the big ones we're seeing, and we're only gonna see more of that as more AI generated code continues to get pushed out.”
quote is from the automated transcript, cleaned for reading: filler sounds and stutters are removed, nothing is rephrased. names can be misheard (the analysis reads context, assessments check outside sources). how →