The expansion brings NetRise’s Provenance engine into the earliest stages of software creation. By evaluating dependency manifests in real-time, the new VS Code extension provides developers with immediate feedback and one-click remediation for flagged packages. This same policy enforcement extends to the command line and AI assistants like Claude Code, Gemini, and Codex, ensuring that automated dependency installs adhere to the same security standards as manual coding.
In section Releases
NetRise Shifts Supply Chain Security Into Developer Workflows
Austin-based security firm NetRise is moving beyond reactive patching by integrating package trust enforcement directly into the developer experience. The company’s new Provenance tools for Visual Studio Code, command-line interfaces, and AI coding assistants aim to block malicious dependencies before they ever reach a project’s build pipeline.

Co-Founder and CTO Michael Scott noted that the window of exposure for supply chain attacks is often measured in hours, yet the damage occurs instantly as malicious packages propagate through automated build and deployment systems. By shifting this defense to the developer’s machine, NetRise aims to prevent compromised code from ever entering the environment. The platform currently supports the Python ecosystem, with plans to expand to additional languages as it integrates further into enterprise development lifecycles.
Comments (0)
No comments yet. Be the first!