More Dev Interrupted episodes

Many tokens make all bugs shallow & open sources new maintainers | Chainguard's Dan Lorenc thumbnail

Many tokens make all bugs shallow & open sources new maintainers | Chainguard's Dan Lorenc

Published 17 Mar 2026

Duration: 2397

AI is reshaping engineering by accelerating development through code generation but introduces security risks, infrastructure challenges, and supply chain vulnerabilities, demanding human oversight, robust safety protocols, and balanced innovation with adaptability, education, and cultural security prioritization.

Episode Description

Autonomous agents are pushing deployment speeds to the absolute limit, but is our security infrastructure ready for the consequences? Andrew sits down...

Overview

The text discusses the transformative impact of AI on engineering practices, particularly through agentic systems that automate code generation and development workflows. AI tools like GitHub Copilot and advanced language models are shifting from autocomplete assistance to full code creation, accelerating software development but introducing risks such as security debt and vulnerabilities in infrastructure. This transition is likened to moving from manual "hand tools" to "power tools," enabling speed but requiring new safeguards due to heightened complexity and potential for errors. Engineers must balance trust in AI-generated code with rigorous security measures, including automated testing, deployment gates, and human oversight, to mitigate risks like accidental data deletion or system instability.

The text also highlights challenges in the global software supply chain, as agentic systems scale and introduce dependencies on third-party tools and open-source projects. Cybersecurity becomes increasingly critical, with attackers leveraging rapid technological advancements while defenders lag behind due to delayed adoption of new tools. Open-source projects face sustainability issues, such as project abandonment and the need for automated maintenance via agents to manage updates and security patches. The role of AI in open source is debated, with potential for efficiency gains but also concerns about noise in vulnerability reports and the erosion of community-driven maintenance. Analogies like "bowling bumpers" and "guardrails" emphasize the importance of structured constraints and reliable CI/CD pipelines to ensure safety and scalability in AI-driven workflows.

Key themes also address the economic and technical trade-offs between using external tools versus custom development, the evolution of open-source collaboration models, and the need for redefining value exchange systems to sustain innovation. AI is seen as both a tool for democratizing engineering and a force that could reshape software ecosystems, requiring a balance of adaptability, risk awareness, and human oversight. The future of engineering involves integration of agentic systems with strong safety protocols, proactive security strategies, and reimagined workflows that harmonize automation with the enduring necessity of human expertise.

Recent Episodes of Dev Interrupted

24 Mar 2026 Why AI-assisted PRs merge at half the rate of human code | LinearBs 2026 Benchmarks

The 2026 Engineering Benchmark Report reveals that while 88.3% of developers use AI regularly, AI-generated pull requests face low merge rates (32.7%), larger sizes, and prolonged reviews due to systemic issues like poor data quality, inadequate policies, and organizational gaps, emphasizing the need for governance, smaller focused PRs, and foundational practices to optimize AI's potential in engineering workflows.

More Dev Interrupted episodes