Dependency Firewall: Block risky packages before the build
GitLab introduces Dependency Firewall to block risky packages before builds, citing attacks involving malicious PyPI packages that run during installation and steal CI/CD credentials. GitLab says AI coding agents can also add unreviewed open-source dependencies, leaving developers less oversight of package risks.
Dependency attacks can expose CI/CD credentials, and automated additions by coding agents make package controls increasingly relevant to software teams.