Videos LqLoYksJ6do
We Gave an Agent Production Code Access and Then Tried to Sleep at Night — Moritz Johner, Form3
Scene timeline
51 shot(s).
keyframes kept every frame deduplicated
What was stored
- cues
- 263
- whisperx 263
- chunks
- 39
- from 263 cues
- keyframes
- 15
- kept of 51 captured
- frames with text
- 15
- 263 lines read
- chapters
- 0
- from the source metadata
- keyframe bytes
- 5.0 MB
- word timings on 263 cues
Provenance
| stage | state | model | started | took |
|---|---|---|---|---|
fetch |
done | — | 2026-08-10 03:51 | 1m 52s |
stt |
done | — | 2026-08-10 03:53 | 23s |
chunk |
done | — | 2026-08-10 03:53 | 0s |
text_embed |
done | — | 2026-08-10 19:46 | 1s |
keyframe |
done | — | 2026-08-10 03:53 | 2m 05s |
ocr |
done | — | 2026-08-10 03:55 | 5s |
frame_embed |
done | — | 2026-08-10 19:46 | 2s |
Frames, and what the machine read
-
- AlEngineer0.96
- World's Fair0.97
-
- AlEngineer0.95
- World's Fair0.99
-
- LAB & PLATINUM SPONSORS0.98
- Amazon AGI Lab0.98
- ANTHROP\C1.00
- Google DeepMind1.00
- MINIMAX0.94
- OpenAI0.92
- Akamai1.00
- arize1.00
- aws1.00
- Braintrust bright data0.99
- B1.00
- Browserbase1.00
- docker1.00
- :neo4j0.93
- ORACLE1.00
- PayPal1.00
- qodo1.00
- reducto1.00
- Sonar1.00
- Makers of0.99
- togetherai1.00
- Unblocked1.00
- WorkOS1.00
- SonarQube1.00
-
- AlEngineer0.97
- World'sFair0.96
- PRESENTED BY1.00
- PITCH0.64
- Microsoft1.00
- We Gave an Agent Production Code Access1.00
- and Then Tried to Sleep at Night0.99
- Engineering the future of Al1.00
- World'sFair1.00
-
- AlEngineer0.97
- World'sFair0.97
- PRESENTED BY1.00
- Dependabot exists. Renovate exists.1.00
- Microsoft1.00
- Problem solved.1.00
- TRACK 5· JUNE 30, 20260.95
- Security1.00
- World'sFair1.00
-
- AlEngineer0.98
- World's Fair0.96
- Problem11.00
- They patch the manifest.1.00
- Everything else is invisible.1.00
- TRACK 5· JUNE 30, 20260.96
- Security1.00
- World'sFair0.98
-
- AlEngineer0.97
- World'sFair0.96
- Problem11.00
- They patch the manifest.1.00
- Everything else is invisible.1.00
- TRACK 5· JUNE 30, 20260.96
- Security1.00
- World'sFair1.00
-
- AlEngineer0.96
- World'sFair1.00
- A useful coding agent is a supply chain0.98
- actor. Whether you planned for that or not1.00
- TRACK 5· JUNE 30, 20260.95
- World'sFair1.00
- Security1.00
-
- AlEngineer0.99
- World's Fair0.99
- PRESENTED BY1.00
- assessment1.00
- read repo1.00
- cve-remediation1.00
- invoke1.00
- agent1.00
- create PR1.00
- + watch Cl0.97
- PR remediation1.00
- if needed1.00
- invoke1.00
- agent1.00
- post PR comment1.00
- send slack notifications1.00
- Microsoft1.00
- TRACK 5· JUNE 30, 20260.97
- Security1.00
- World's Fair0.99
Transcript
263 cues· 3,731 words· 19,875 chars
- 0:13 Thanks, everyone, for joining in.
- 0:14 Thanks for the great intro, by the way.
- 0:17 So my talk today is about some titles we gave on Azure production code access and then tried to sleep at night.
- 0:24 So it's mostly around dependency patching, which is probably the most glamorous problem in software engineering.
- 0:33 I guess everyone did it here at some point in the past.
- 0:37 It really is like vacuuming like everyone loves it kind of way to do it again next week now at our scale we have thousands of repositories and it really is a backlog that never empties and Because 10 inches today and you know next week 20 more will arrive and you have to deal with them So naturally you think sure Which is automated depend about exists renovate exists problem solved, right?
- 1:03 It isn't
- 1:04 Because these tools were really built for a world where fixing a CVE means looking at the manifest in a repository and just bumping a version to the next version, and that's it.
- 1:17 But our world is much more complicated than that, at least nowadays, since we have containers.
- 1:22 So the first problem is that the vulnerable thing isn't necessarily the thing that these tools can see.
- 1:28 For instance, the CVE might live in an OS package that you use in your base image.
- 1:32 It's not in your Docker file.
- 1:34 It's just in the base image.
- 1:36 Or if your Docker file pulls down a binary during the build process, it may see the URL, which might contain a version number, but it has no idea how to act on it.
- 1:45 So they can only look at the manifest, patch the manifest, but everything else is just simply invisible.
- 1:52 Now, the second problem is patches never happen in isolation.
- 1:57 So when we look at the Go code base, sometimes you want to bump the Go runtime to the next minor version.
- 2:02 When you do that, sometimes you might have to also bump the Go linter, because the versions are just intertwined.
- 2:08 You have to bump both of them at the same time.
- 2:11 So when you bump the linter, that sometimes introduces new linting rules, which then invalidates the code base.
- 2:16 And you're left with this big mess.
- 2:19 Now, these old tools, quote unquote old tools, Dependabot and Renovatebot, well, they just bump the Go runtime version, create a PR, and walk away.
- 2:27 And you're just left with this mess.
- 2:28 And you need to figure out how to fix that.
- 2:36 So you don't really have a patching problem.
- 2:39 You also have a reasoning problem that you need to address here.
- 2:44 You really want to have a tool that looks at the CV and understands the full surface of it.
- 2:48 Where does the CV actually live?
- 2:50 And it needs to figure out what else needs to move in order to get to a green CI.
- 2:57 So that's basically what we did.
- 2:59 We built Patch Pilot.
- 3:01 We pushed the production.
- 3:03 Eventually, InfoSec came around the corner and asked a very reasonable question.
- 3:07 Is this automation, or is it a supply chain that's been waiting to happen?
- 3:12 A useful coding agent is a supply chain actor, whether you plan for that or not.
- 3:17 That's the thesis of this talk, basically.
- 3:20 It's not agents are dangerous or agents are fine.
- 3:22 It's the moment where you give an agent production credentials in order to be useful.
- 3:29 It really becomes a supply chain actor, just like an engineer in your department.
- 3:33 And you should apply similar or the same guardrails for the agent, just as you do for engineers.
- 3:41 Now, this is a case study.
- 3:41 We built this.
- 3:42 We ran it in production.
- 3:43 InfoSec pushed back in several places.
- 3:45 They were right.
- 3:46 I just want to present to you what we came up with in the end.
- 3:50 It's nothing new.
- 3:50 It's nothing fancy.
- 3:52 I just want to share what we did and then hopefully have a discussion afterwards to see how we all figure this out together.
- 4:01 Now, PatchPilot has two layers.
loading