惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
博客园 - 【当耐特】
月光博客
月光博客
Vercel News
Vercel News
D
Docker
I
InfoQ
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
GbyAI
GbyAI
有赞技术团队
有赞技术团队
雷峰网
雷峰网
博客园 - 聂微东
小众软件
小众软件
Y
Y Combinator Blog
腾讯CDC
L
LangChain Blog
The GitHub Blog
The GitHub Blog
宝玉的分享
宝玉的分享
Stack Overflow Blog
Stack Overflow Blog
大猫的无限游戏
大猫的无限游戏
T
The Blog of Author Tim Ferriss

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders
Introducing Semgrep Guardian: Real-Time Security for AI-W...
Austin Theriault · 2026-06-24 · via Hacker News - Newest: "AI"

Two years ago, a human wrote every line of code that went into production. Today, that's no longer true.

Two shifts are reshaping the industry:

  1. Traditional engineers are writing more software than ever before, powered by AI agents, and reviewing far less of it. 

  2. Citizen developers, people who have never written code before, are now pushing production software connected to customer data every single day.

The result: the volume of unreviewed code is skyrocketing. In addition, frontier models are accelerating the discovery and exploitation of software vulnerabilities, compressing the window between disclosure and attack. Across the industry, AppSec teams are seeing 10x the vulnerabilities they were two years ago.

On top of this, our traditional gates are breaking down. Human review is finite, and most tooling runs in CI/CD after code is already written, which is too late. Using models alone to check themselves is too slow, and too expensive to work at scale.

The industry desperately needs a solution that moves away from noisy findings and toward real security outcomes.

What is Semgrep Guardian?

Semgrep is the code security platform trusted by hundreds of the world's best security teams, including Notion, Snowflake, and Dropbox. Guardian is Semgrep's solution for agentic code security, purpose-built to scan and fix AI-generated code the moment it's written.

Guardian lives in your IDE, detecting and fixing the vulnerabilities, malicious packages, and hardcoded secrets your agent introduces. We're an official partner of Cursor and Claude Code, and work wherever an MCP server is supported, including out-of-the-box integrations for GitHub Copilot, VS Code, Windsurf, Amazon Kiro, and many others. Guardian comes bundled with an MCP server, Hooks integrations, and Skills. Together, they ensure Semgrep is always available to the agent at exactly the right moment. When an agent catches and resolves a vulnerability at the moment it's written, it happens faster and cheaper than finding it downstream.

Here's what's possible on day one:

Scan everything, automatically. Prevent your agent from introducing the vulnerabilities that matter most: OWASP Top 10 issues, malicious open source packages, and hardcoded secrets. Every file an agent touches is scanned automatically, powered by Semgrep's multimodal engine across Code, Supply Chain, and Secrets.

Complete visibility. Your security team gets a complete picture of what's happening across your engineering org. Track how many issues agents introduced, how many were caught and fixed automatically, which IDEs and agents your team is using, and the overall ROI of your program. 

Deploy in an afternoon. Easily roll out to hundreds of developers without any software installed on their machines. Use your MDM or your agent's built-in enterprise controls to get everyone running with security guardrails from day one.

Semgrep Guardian is an always-on security layer that developers rarely think about, and security teams can trust.

The cheapest vulnerability is the one your agent never ships

Across our customer base, Guardian runs over 3 million scans every week, with 95% completing in under 5 seconds. It’s fast enough to run inline, without slowing anyone down.

One B2B SaaS company rolled out Guardian across their engineering team and now has full visibility into every line of code their agents write. Since deploying, they prevent over 180 critical issues every week, issues that would have otherwise gone undetected until much later in the process, when they're significantly more expensive and time-consuming to fix. 

Try Semgrep Guardian today

Install Guardian now for free, or watch a 60-second video to see it in action.