We Gave an Agent Production Code Access and Then Tried to Sleep at Night — Moritz Johner, Form3
Summary
This talk addresses the complex challenge of dependency patching in large-scale production codebases, highlighting limitations of automated tools like Dependabot and Renovate. It explains how vulnerabilities can exist in OS packages or binaries outside of standard manifests, and how dependency updates are often intertwined, leading to cascading issues. The key takeaway is that patching is not just a technical problem, but also a logistical one that requires a more comprehensive approach than current automation offers.