AI Coding Is the New Software Supply Chain Risk
The question is no longer "Is AI dangerous?" — it's "Who verifies the code AI writes, and how?" The Wrong Question Discussions around AI coding often get stuck on one point: "Is AI dangerous?" But th
Search for a command to run...
The question is no longer "Is AI dangerous?" — it's "Who verifies the code AI writes, and how?" The Wrong Question Discussions around AI coding often get stuck on one point: "Is AI dangerous?" But th
Scanning finds what's wrong with the code. It doesn't answer how the code got there. The Assumption That No Longer Holds Every code scanning tool — Semgrep, Snyk, CodeQL, GitHub Advanced Security —
They inspect the house after the guest is already inside. leeh checks the guest at the door. The Obvious Question "Semgrep and Snyk already scan code for vulnerabilities. Why do I need leeh?" It's a
Your security team isn't protecting you from AI threats. They're protecting you from AI benefits. The Elephant in Every Enterprise It's 2026. Claude writes production-grade code. GPT-4 refactors leg