When AI Agents Break DevOps:
Securing Pipelines from Autonomous Workflows
2026.11.12 JFrog-LandingPage-1540x660-1

Sponsored By:

JFrog Logo
Thursday, November 12th

3:00 pm CET

When the self-replicating Shai-Hulud attack hit the software supply chain, it started with an AI agent pulling in a package that nobody checked and began infecting npm package registries to steal developer credentials, leak sensitive cloud keys, and more. As AI agents take on more coding and dependency selection, this is exactly the risk modern teams face: untrusted or malicious packages slipping into the codebase unchecked.

Take a journey through a live exploit with prominent DevOps Engineer and tech influencer Francesco Ciulla, who brings deep experience in cloud-native systems and AI-assisted development, alongside JFrog Solutions Architect Mark Whitby.

In this hands-on session, they will build a real application using AI agents, allowing you to see in real time how risky, immature, and malicious packages attempt to slip into your IDE, local environment, and CI pipeline. From there, they’ll show how JFrog stops it without slowing down development.

What you'll leave with:

- Where AI-assisted development introduces supply chain risk across the workflow.

- How to block risky dependencies before they reach your codebase.

- How to enforce controls in CI/CD so risky packages get caught before they ship.

 

See real attacks in a live build and a practical way to ship fast without creating hidden risk.

Register Below:

We'll send you an email confirmation

Francesco-Ciulla-Speaker-modified

Francesco Ciulla

Develope Advocate, Creator and Tech Lead - JFrog
Mark-Whitby-Speaker-2026-modified

Mark Whitby

Solution Architect - JFrog