# AI coding tools can increase dependency and npm supply-chain risks

DevFeed: [AI coding tools can increase dependency and npm supply-chain risks](<https://devfeed.tech/articles/ai-coding-security-risks-demand-dependency-firewalls-13361.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/ai-coding-security-risks-demand-dependency-firewalls>)

Author: Shibam Dhar

Published: 2026-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [ai-coding](<https://devfeed.tech/topics/ai-coding.md>), [Security](<https://devfeed.tech/topics/security.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>)

## AI overview

The article explains that AI coding assistants can rapidly introduce vulnerable, malicious, or non-compliant open-source dependencies. It presents Harness Artifact Registry's Dependency Firewall as a registry-level control point for evaluating and blocking risky packages before they enter a CI/CD pipeline.

## Source excerpt

AI coding tools can introduce vulnerable dependencies fast. Learn how dependency firewalls block risky packages at the registry level. Explore now. | Blog