Endor Labs Releases Insightful Report on Dependency Management
This annual report unveils vital information about how AI-generated code and integrations are transforming the software supply chain landscape.
Endor Labs, recognized as a leading firm in application security, has published the latest edition of its annual report titled State of Dependency Management 2025: Security in the AI-Code Era. This report, now in its fourth release, emphasizes a critical finding: AI-assisted development has transitioned from a futuristic concept to a present reality, presenting a significant risk as organizations unwittingly adopt code with unknown vulnerabilities.
The investigation centered around the safety of dependency versions suggested by AI coding assistants, revealing a startling statistic—only 20% of these AI-recommended dependencies are deemed safe. With the swift adoption of Model Context Protocol (MCP) servers that link AI tools to numerous third-party integrations, the pressure on enterprises to manage these new risks has intensified.
Key Findings from the Dependency Management Report
The comprehensive analysis conducted by Endor Labs focused on over 10,000 GitHub repositories, evaluating the security implications of AI suggestions across popular ecosystems like PyPI, npm, Maven, and NuGet. From this extensive analysis, several important insights emerged:
High Vulnerability Rates in AI-Recommended Dependencies
In reviewing dependencies imported by various AI models, it was discovered that between 44% to 49% possessed known security vulnerabilities. This emphasizes that even established dependencies can introduce risks to organizations that do not undertake proper vetting.
Improving Results with Security Tools
When equipped with effective security tools, AI coding agents significantly improve their recommendations, with safe dependency suggestions rising from around 20% to an impressive 57%—showing almost a threefold enhancement. This indicates that while AI tools can enhance productivity, without diligent monitoring, organizations may remain at risk.
The Need for Better Governance in the MCP Ecosystem
The rapid innovation pace has led to the establishment of over 10,000 MCP servers within a year, yet alarming statistics show that approximately 40% of these lack appropriate licensing. Many were developed by individuals not adhering to enterprise-level security standards, exposing systems to further vulnerabilities as many interact with sensitive APIs.
Henrik Plate, Security Researcher at Endor Labs, commented on the integration of AI in development: "AI coding agents have become essential in modern development workflows, introducing a new array of potential vulnerabilities. As numerous third-party MCP servers emerge, the necessity for robust verification protocols becomes increasingly clear. Achieving a balance between innovative progress and stringent governance is crucial for safeguarding critical systems from potential exploitation."
Next Steps for Organizations
The insights from the State of Dependency Management 2025 report emphasize the imperative actions organizations need to adopt to mitigate risks effectively. Understanding the safety of AI-suggested code is critical, but it is equally important to implement sufficient verification measures to protect vital infrastructure against potential threats.
By reinforcing governance structures and integrating comprehensive security protocols, organizations can confidently leverage AI innovations while minimizing the chances of introducing compromised dependencies into their systems. Taking these actions can significantly reduce the attack surface and spur more secure application development.
Frequently Asked Questions
What is the main focus of the Endor Labs report?
The report primarily examines the risks associated with AI-generated dependencies in software development, highlighting the prevalence of vulnerabilities.
How many dependencies suggested by AI are considered safe?
Only about 20% of the dependency versions recommended by AI coding assistants are deemed safe for use.
What percentage of AI-imported dependencies contained vulnerabilities?
According to the findings, 44% to 49% of dependencies suggested by AI coding agents had known security vulnerabilities.
What role do security tools play in AI dependency management?
Security tools can significantly enhance the safety of AI dependency recommendations, increasing safe suggestions from 20% to 57%.
Why is governance important in the MCP ecosystem?
Strong governance is essential to ensure that organizations can safely adopt AI innovations without exposing their systems to unverified and potentially harmful code.