AI agents are getting good at probing the boundaries developers put around them. Their ability to improvise makes them hard to contain. “You ask for something in a very high-level, vague-at-best way. You walk away, and you come back to a remarkable pile of mostly working software. But you then realize that you gave a probabilistic machine access to your life and your systems,” said Docker President and COO Mark Cavage, speaking to the crowd at the opening session of the WeAreDevelopers North America conference in San Jose Thursday. During his keynote, Cavage unveiled a new specification for packaging an AI agent and its tools together with a declaration of the access it requests from a sandbox. He also announced that Docker plans to contribute the new specification to the Cloud Native Computing Foundation. A Common Format for Agent Sandboxes Published under the Apache 2.0 license, the specification is meant to give developers and sandbox providers a common format they can use acr...
A survey of 400 platform and security engineers in the U.S and United Kingdom (UK), finds nearly three quarters (73%) are either only moderately confident (58%) or not confident (15%) in the ability of their existing tools for managing software artifacts to prevent attacks against their organization’s software supply chain. Conducted by Cloudsmith, a provider of a platform for managing software artifacts, the survey also finds nearly half of respondents (48%) can identify an intrusion in their software supply chain but need to rely on manual efforts to enforce some type of quarantine or resolve the issue. Only 37% said they can automatically identify, block, and trace an intrusion within minutes. As a result, nearly two thirds (65%) are either investigating a different approach to compliance (45%) or are evaluating some type of security framework (25%), the survey finds. Cloudsmith CEO Glenn Weinstein said that as it becomes more apparent in the AI era that changes will be made to h...