{"id":105651,"date":"2025-11-19T16:22:06","date_gmt":"2025-11-19T14:22:06","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?p=105651"},"modified":"2026-04-23T23:39:40","modified_gmt":"2026-04-23T21:39:40","slug":"revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide","status":"publish","type":"post","link":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/","title":{"rendered":"Revolutionizing SCA\u00a0With Agentic AI: How\u00a0Checkmarx\u00a0Developer Assist\u00a0Transforms\u00a0Open-Source\u00a0Security\u00a0Within the IDE\u00a0"},"content":{"rendered":"<p>Revolutionizing SCA&nbsp;with Agentic AI: How&nbsp;Checkmarx&nbsp;<em>Developer Assist<\/em>&nbsp;Transforms&nbsp;Open-Source&nbsp;Security&nbsp;within the IDE&nbsp;<\/p>\n\n\n\n<p>Software Composition Analysis (SCA) has become an essential pillar of modern application security, helping&nbsp;organizations&nbsp;identify&nbsp;vulnerabilities, malicious components, and licensing issues&nbsp;within&nbsp;open-source&nbsp;dependencies.&nbsp;<\/p>\n\n\n\n<p>Traditional SCA solutions scan codebases to detect risky packages, providing security teams with critical visibility into their open-source attack surface. However, the typical SCA workflow\u2014scanning code&nbsp;at&nbsp;specific stages&nbsp;in the software development lifecycle (SDLC) and then cycling back to remediate issues\u2014creates friction, delays releases, and frustrates developers who must context-switch away from active development to address security findings.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\">SCA,&nbsp;Shifted&nbsp;All-the-Way&nbsp;Left&nbsp;<\/h2>\n\n\n\n<p>The true value of SCA&nbsp;emerges&nbsp;when it&nbsp;is embedded directly into the developer\u2019s workflow, providing real-time feedback within the integrated development environment (IDE) where&nbsp;the&nbsp;code is written. By shifting security left into the IDE, developers receive immediate alerts about vulnerable or malicious dependencies as they work, rather than discovering&nbsp;problems days or weeks later during&nbsp;code&nbsp;commit or&nbsp;CI\/CD pipeline scans.&nbsp;<\/p>\n\n\n\n<p>This real-time approach prevents security debt from accumulating, reduces the cost and effort of remediation, and empowers developers to make secure choices&nbsp;as they create their code. When SCA becomes an integrated,&nbsp;continuous process rather than a disruptive checkpoint, security transforms from a bottleneck into an enabler of faster, safer development.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\">Introducing&nbsp;Agentic AI for SCA&nbsp;<\/h2>\n\n\n\n<p>Checkmarx&nbsp;is already a leading SCA provider through its&nbsp;Checkmarx&nbsp;One platform, but the recent introduction of the agentic-AI&nbsp;<em>Developer Assist<\/em>&nbsp;takes this functionality to an entirely new level.&nbsp;Developer Assist\u2019s agentic AI&nbsp;core&nbsp;changes the SCA&nbsp;dynamic, because&nbsp;it is constantly on the lookout for problems and is always ready to act on behalf of the developer, all within the IDE.&nbsp;<\/p>\n\n\n\n<p>Developer Assist fundamentally transforms&nbsp;the&nbsp;traditional&nbsp;SCA&nbsp;experience by introducing agentic AI capabilities that continuously&nbsp;and actively&nbsp;monitor, analyze, and remediate&nbsp;OSS&nbsp;dangers&nbsp;without breaking developer flow&nbsp;\u2013 instead of&nbsp;forcing developers to reopen closed code bases later.&nbsp;&nbsp;<\/p>\n\n\n\n<p>At its core, Developer Assist provides ongoing background SCA scanning of open-source package dependencies during all code writing activities,&nbsp;whether the code is written by humans or provided by generative AI tools.&nbsp;<\/p>\n\n\n\n<p>This continuous monitoring&nbsp;extends to&nbsp;whenever manifest files are&nbsp;modified. Supported&nbsp;manifest&nbsp;file&nbsp;types&nbsp;currently&nbsp;include:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>.NET (csproj,&nbsp;directory.packages.props,&nbsp;packages.config)&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Maven (pom.xml)&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>npm&nbsp;(package.json)&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>PyPI&nbsp;(requirements.txt)&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Go (go.mod)&nbsp;&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>This breadth of coverage ensures that regardless of their&nbsp;technology stack, developers receive consistent&nbsp;and&nbsp;accurate&nbsp;real-time security feedback.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\">The&nbsp;<em>Safe Refactor<\/em>&nbsp;Revolution&nbsp;&nbsp;<\/h2>\n\n\n\n<p>The&nbsp;most far-reaching&nbsp;innovation of Developer Assist lies in its ability to not just&nbsp;identify&nbsp;open-source&nbsp;dependency&nbsp;problems but to&nbsp;<em>autonomously resolve them<\/em>&nbsp;with intelligent, context-aware remediation.&nbsp;&nbsp;<\/p>\n\n\n\n<p>When a vulnerable&nbsp;or malicious&nbsp;package is detected, the&nbsp;developer can launch&nbsp;agentic-AI&nbsp;<em>Safe Refactor<\/em>&nbsp;capabilities&nbsp;that&nbsp;<em>automatically generate&nbsp;code changes<\/em>&nbsp;directly within the IDE, complete with step-by-step explanations that developers can review and approve before implementation.&nbsp;<\/p>\n\n\n\n<p>Safe Refactor&nbsp;first attempts to replace&nbsp;a&nbsp;dangerous package with&nbsp;a&nbsp;safe version of the same package.&nbsp;In cases where&nbsp;no safer version exists,&nbsp;Safe Refactor&nbsp;leverages&nbsp;the developer\u2019s&nbsp;generative AI&nbsp;tools&nbsp;(e.g., Cursor&nbsp;or&nbsp;GitHub Copilot)&nbsp;to suggest alternative packages with similar functionality, ensuring developers&nbsp;aren\u2019t&nbsp;blocked,&nbsp;without a path forward.&nbsp;<\/p>\n\n\n\n<p>Beyond simple package swaps,&nbsp;Safe Refactor&nbsp;demonstrates&nbsp;sophisticated&nbsp;understanding of dependency ecosystems by detecting when other related open-source packages also need replacement to ensure compatibility with newly introduced packages. This&nbsp;holistic approach&nbsp;prevents the cascade of compatibility issues that often plague manual security remediation efforts, where fixing one dependency breaks another.&nbsp;But there is even more\u2026&nbsp;<\/p>\n\n\n\n<p>The crown jewel of Developer Assist is&nbsp;how&nbsp;Safe&nbsp;Refactor&nbsp;autonomously&nbsp;handles&nbsp;the complex code-level changes that package updates often require, saving developers vast amounts of time and effort:&nbsp;Safe Refactor automatically detects breaking changes introduced by replaced packages and makes the necessary&nbsp;code&nbsp;modifications so that calls to updated packages\u2019&nbsp;methods and functions continue to operate as expected.&nbsp;<\/p>\n\n\n\n<p>Developers can interactively chat with the AI agent to&nbsp;ask questions and&nbsp;refine remediation suggestions,&nbsp;maintaining&nbsp;control over the process while&nbsp;benefiting&nbsp;from&nbsp;cutting-edge&nbsp;AI&nbsp;assistance.&nbsp;&nbsp;<\/p>\n\n\n\n<p>After developers approve suggestions, Safe Refactor runs tests to ensure&nbsp;that the&nbsp;modified application code compiles and functions correctly, even creating new tests when relevant existing&nbsp;tests&nbsp;aren\u2019t&nbsp;found&nbsp;in the project.&nbsp;<\/p>\n\n\n\n<iframe width=\"560\" height=\"315\" src=\"https:\/\/www.youtube.com\/embed\/PtE_iQ1V0Kc?si=DZfHFuMBjvBduCF-\" title=\"YouTube video player\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n\n\n\n<p><em>Watch a demo&nbsp;showing&nbsp;Developer Assist\u2019s&nbsp;Safe Refactor&nbsp;in action.<\/em>&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-4\">Developer Assist for SCA Saves Time and Improves Security&nbsp;<\/h2>\n\n\n\n<p>The time savings delivered by Developer Assist are substantial for both development teams and application security professionals. Tasks that previously consumed hours&nbsp;\u2013&nbsp;researching package alternatives, rewriting function calls, ensuring compatibility, and running post-remediation tests&nbsp;\u2013&nbsp;are now&nbsp;almost completely&nbsp;automated.&nbsp;<\/p>\n\n\n\n<p>In fact,&nbsp;very conservative&nbsp;Checkmarx&nbsp;benchmarks&nbsp;indicate&nbsp;that upgrading dependencies&nbsp;is&nbsp;up to 70% faster with assisted code&nbsp;refactoring, saving&nbsp;approximately&nbsp;$420 per upgrade&nbsp;in developer time.&nbsp;<\/p>\n\n\n\n<p>This efficiency enables developers to&nbsp;maintain&nbsp;their productivity, creative flow, and innovation instead of being pulled into time-consuming security firefighting. Meanwhile,&nbsp;AppSec teams can better focus on strategic security initiatives rather than being mired in&nbsp;triaging SCA findings and&nbsp;tracking&nbsp;support tickets.&nbsp;<\/p>\n\n\n\n<p>The benefits of Developer Assist for SCA extend far beyond mere convenience. From a security perspective, continuous&nbsp;background&nbsp;SCA scanning means&nbsp;that&nbsp;vulnerable&nbsp;and malicious packages&nbsp;are caught&nbsp;immediately, rather than lingering undetected until the next scheduled scan. More vulnerable and malicious packages get remediated because the friction of remediation has been dramatically reduced; developers are far more likely to address issues when an AI agent can handle the heavy lifting.&nbsp;<\/p>\n\n\n\n<p>Developer Assist&nbsp;leverages&nbsp;Checkmarx\u2019s&nbsp;industry-leading&nbsp;open-source vulnerability intelligence&nbsp;database.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Unlike many SCA tools that simply&nbsp;aggregate and&nbsp;republish public data,&nbsp;Checkmarx\u2019s&nbsp;CVE database&nbsp;is vetted by&nbsp;in-house&nbsp;expert&nbsp;security analysts&nbsp;who&nbsp;validate&nbsp;and&nbsp;contextualize&nbsp;each CVE&nbsp;entry, reducing false positives and highlighting real threats.&nbsp;<\/p>\n\n\n\n<p>Going even further,\u00a0Developer Assist\u00a0identifies\u00a0malicious\u00a0and suspicious\u00a0packages (which are not included in CVE databases),\u00a0by\u00a0automatically\u00a0querying\u00a0Checkmarx\u2019s\u00a0proprietary\u00a0<a href=\"https:\/\/checkmarx.com\/malicious-packages-identification-api\/\" target=\"_blank\" rel=\"noreferrer noopener\">database of malicious packages<\/a>, which is the largest available anywhere\u00a0(currently\u00a0containing\u00a0over 420,000 entries). If a package\u00a0in a project\u00a0is classified as\u00a0malicious or\u00a0suspicious, the developer\u00a0is\u00a0alerted\u00a0in the IDE so that rapid remediation can occur.\u00a0<\/p>\n\n\n\n<p>In brief, Developer Assist&nbsp;represents&nbsp;a&nbsp;pure shift-left&nbsp;methodology,&nbsp;bringing early&nbsp;security resolution&nbsp;into&nbsp;the IDE&nbsp;in real-time,&nbsp;rather than forcing the costly cycle of&nbsp;commit or&nbsp;CI\/CD scan failures followed by code fixes and re-scans. By resolving issues before code ever leaves the developer\u2019s machine, organizations reduce pipeline delays, accelerate&nbsp;release&nbsp;velocity, and build security into their culture rather than bolting it on afterward.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-5\">Join the AI-Driven SCA&nbsp;Paradigm Shift&nbsp;<\/h2>\n\n\n\n<p>The evolution from traditional&nbsp;scan-and-alert&nbsp;SCA to continuous&nbsp;AI-driven&nbsp;security monitoring&nbsp;and remediation automation&nbsp;represents&nbsp;a paradigm shift&nbsp;in how organizations can protect their software supply chain without sacrificing developer&nbsp;speed&nbsp;or experience. Developer Assist&nbsp;doesn\u2019t&nbsp;just make SCA more&nbsp;convenient,&nbsp;it fundamentally reimagines what\u2019s possible when intelligent automation meets security&nbsp;expertise.&nbsp;<\/p>\n\n\n\n<p>Ready to transform your SCA approach and empower your developers with agentic AI security&nbsp;assistance? Learn more about Developer Assist or request a personalized demo of <a href=\"https:\/\/checkmarx.com\/product\/checkmarx-one-assist\/\" target=\"_blank\" rel=\"noreferrer noopener\">Checkmarx One Assist<\/a>&nbsp;and&nbsp;see how&nbsp;Checkmarx&nbsp;is&nbsp;revolutionizing&nbsp;security&nbsp;within&nbsp;enterprise&nbsp;development workflows.&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a href=\"https:\/\/checkmarx.com\/product\/developer-assist\/\"><img decoding=\"async\" width=\"600\" height=\"75\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Learn-more-about-Developer-Assist.webp\" alt=\"\" class=\"wp-image-105655\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Learn-more-about-Developer-Assist.webp 600w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Learn-more-about-Developer-Assist-300x38.webp 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Learn-more-about-Developer-Assist-400x50.webp 400w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p><\/p>","protected":false},"excerpt":{"rendered":"<p>Revolutionizing SCA&nbsp;with Agentic AI: How&nbsp;Checkmarx&nbsp;Developer Assist&nbsp;Transforms&nbsp;Open-Source&nbsp;Security&nbsp;within the IDE&nbsp; Software Composition Analysis (SCA) has become an essential pillar of modern application security, helping&nbsp;organizations&nbsp;identify&nbsp;vulnerabilities, malicious components, and licensing issues&nbsp;within&nbsp;open-source&nbsp;dependencies.&nbsp; Traditional SCA solutions scan codebases to detect risky packages, providing security teams with critical visibility into their open-source attack surface. However, the typical SCA workflow\u2014scanning code&nbsp;at&nbsp;specific stages&nbsp;in the [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":105659,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1284,84,1424,845,1280,844],"tags":[1452,178,1447],"class_list":["post-105651","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-llm-tools-in-application-security","category-blog","category-checkmarx-one","category-sca","category-secure-coding-best-practices-for-developers","category-supply-chain-security","tag-developer-assist","tag-sca","tag-suspicious-packages"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Revolutionizing SCA\u00a0With Agentic AI: How\u00a0Checkmarx\u00a0Developer Assist\u00a0Transforms\u00a0Open-Source\u00a0Security\u00a0Within the IDE\u00a0<\/title>\n<meta name=\"description\" content=\"Discover how to use agentic AI to deliver real-time SCA inside the IDE\u2014catching malicious packages instantly and automating safe fixes\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Revolutionizing SCA\u00a0With Agentic AI: How\u00a0Checkmarx\u00a0Developer Assist\u00a0Transforms\u00a0Open-Source\u00a0Security\u00a0Within the IDE\u00a0\" \/>\n<meta property=\"og:description\" content=\"Discover how to use agentic AI to deliver real-time SCA inside the IDE\u2014catching malicious packages instantly and automating safe fixes\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-19T14:22:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-23T21:39:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Untitled-design-11.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"2240\" \/>\n\t<meta property=\"og:image:height\" content=\"1260\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Checkmarx Team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Checkmarx Team\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/\"},\"author\":{\"name\":\"Checkmarx Team\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/25482b0b490209da942049e2c8b0d3aa\"},\"headline\":\"Revolutionizing SCA\u00a0With Agentic AI: How\u00a0Checkmarx\u00a0Developer Assist\u00a0Transforms\u00a0Open-Source\u00a0Security\u00a0Within the IDE\u00a0\",\"datePublished\":\"2025-11-19T14:22:06+00:00\",\"dateModified\":\"2026-04-23T21:39:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/\"},\"wordCount\":1476,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Untitled-design-11.webp\",\"keywords\":[\"developer assist\",\"SCA\",\"suspicious packages\"],\"articleSection\":[\"AI &amp; LLM Tools in Application Security\",\"Blog\",\"Checkmarx One\",\"SCA\",\"Secure Coding Best Practices for Developers\",\"Supply Chain Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/\",\"url\":\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/\",\"name\":\"Revolutionizing SCA\u00a0With Agentic AI: How\u00a0Checkmarx\u00a0Developer Assist\u00a0Transforms\u00a0Open-Source\u00a0Security\u00a0Within the IDE\u00a0\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Untitled-design-11.webp\",\"datePublished\":\"2025-11-19T14:22:06+00:00\",\"dateModified\":\"2026-04-23T21:39:40+00:00\",\"description\":\"Discover how to use agentic AI to deliver real-time SCA inside the IDE\u2014catching malicious packages instantly and automating safe fixes\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Untitled-design-11.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Untitled-design-11.webp\",\"width\":2240,\"height\":1260},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/25482b0b490209da942049e2c8b0d3aa\",\"name\":\"Checkmarx Team\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/cropped-cx_favicon-150x150.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/cropped-cx_favicon-150x150.webp\",\"caption\":\"Checkmarx Team\"},\"url\":\"https:\/\/checkmarx.com\/author\/checkmarx-team\/\"}]}<\/script>\n<meta property=\"og:video\" content=\"https:\/\/www.youtube.com\/embed\/PtE_iQ1V0Kc\" \/>\n<meta property=\"og:video:type\" content=\"text\/html\" \/>\n<meta property=\"og:video:duration\" content=\"257\" \/>\n<meta property=\"og:video:width\" content=\"480\" \/>\n<meta property=\"og:video:height\" content=\"270\" \/>\n<meta property=\"ya:ovs:adult\" content=\"false\" \/>\n<meta property=\"ya:ovs:upload_date\" content=\"2025-11-19T14:22:06+00:00\" \/>\n<meta property=\"ya:ovs:allow_embed\" content=\"true\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Revolutionizing SCA\u00a0With Agentic AI: How\u00a0Checkmarx\u00a0Developer Assist\u00a0Transforms\u00a0Open-Source\u00a0Security\u00a0Within the IDE\u00a0","description":"Discover how to use agentic AI to deliver real-time SCA inside the IDE\u2014catching malicious packages instantly and automating safe fixes","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/","og_locale":"en_US","og_type":"article","og_title":"Revolutionizing SCA\u00a0With Agentic AI: How\u00a0Checkmarx\u00a0Developer Assist\u00a0Transforms\u00a0Open-Source\u00a0Security\u00a0Within the IDE\u00a0","og_description":"Discover how to use agentic AI to deliver real-time SCA inside the IDE\u2014catching malicious packages instantly and automating safe fixes","og_url":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_published_time":"2025-11-19T14:22:06+00:00","article_modified_time":"2026-04-23T21:39:40+00:00","og_image":[{"width":2240,"height":1260,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Untitled-design-11.webp","type":"image\/webp"}],"author":"Checkmarx Team","twitter_card":"summary_large_image","twitter_creator":"@checkmarx","twitter_site":"@checkmarx","twitter_misc":{"Written by":"Checkmarx Team","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/"},"author":{"name":"Checkmarx Team","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/25482b0b490209da942049e2c8b0d3aa"},"headline":"Revolutionizing SCA\u00a0With Agentic AI: How\u00a0Checkmarx\u00a0Developer Assist\u00a0Transforms\u00a0Open-Source\u00a0Security\u00a0Within the IDE\u00a0","datePublished":"2025-11-19T14:22:06+00:00","dateModified":"2026-04-23T21:39:40+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/"},"wordCount":1476,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Untitled-design-11.webp","keywords":["developer assist","SCA","suspicious packages"],"articleSection":["AI &amp; LLM Tools in Application Security","Blog","Checkmarx One","SCA","Secure Coding Best Practices for Developers","Supply Chain Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/","url":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/","name":"Revolutionizing SCA\u00a0With Agentic AI: How\u00a0Checkmarx\u00a0Developer Assist\u00a0Transforms\u00a0Open-Source\u00a0Security\u00a0Within the IDE\u00a0","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Untitled-design-11.webp","datePublished":"2025-11-19T14:22:06+00:00","dateModified":"2026-04-23T21:39:40+00:00","description":"Discover how to use agentic AI to deliver real-time SCA inside the IDE\u2014catching malicious packages instantly and automating safe fixes","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/blog\/ai-llm-tools-in-application-security\/revolutionizing-sca-with-agentic-ai-how-checkmarx-developer-assist-transforms-open-source-security-within-the-ide\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Untitled-design-11.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/11\/Untitled-design-11.webp","width":2240,"height":1260},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/25482b0b490209da942049e2c8b0d3aa","name":"Checkmarx Team","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/cropped-cx_favicon-150x150.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/cropped-cx_favicon-150x150.webp","caption":"Checkmarx Team"},"url":"https:\/\/checkmarx.com\/author\/checkmarx-team\/"}]},"og_video":"https:\/\/www.youtube.com\/embed\/PtE_iQ1V0Kc","og_video_type":"text\/html","og_video_duration":"257","og_video_width":"480","og_video_height":"270","ya_ovs_adult":"false","ya_ovs_upload_date":"2025-11-19T14:22:06+00:00","ya_ovs_allow_embed":"true"},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/105651","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/comments?post=105651"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/105651\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/105659"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=105651"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/categories?post=105651"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/tags?post=105651"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}