What’s in Your Repo?
Episode 93
August 25, 2025
Code repositories may live on the “left” of the software development lifecycle, but their security implications extend all the way through to runtime. In this co-hosted episode, Mark and Dana unpack why repos deserve a central place in any ASPM strategy; especially with the rise of AI-generated code, sprawling open-source dependencies, and code-to-cloud attack paths.
They explore how security teams can:
- Detect secrets, vulnerabilities, and unsafe AI frameworks
- Trace issues from runtime back to the responsible developer
- Classify repos dynamically by risk factors and ownership
- Stay audit-ready with visibility into material code changes
It’s not just about knowing where your code lives—it’s about knowing what’s living in your code.