AI-hallucinated code dependencies become new supply chain risk (www.bleepingcomputer.com)
from neme@lemm.ee to cybersecurity@sh.itjust.works on 12 Apr 21:55
https://lemm.ee/post/61157601

#cybersecurity

threaded - newest

can@sh.itjust.works on 13 Apr 02:50 next collapse

The only way to mitigate this risk is to verify package names manually and never assume a package mentioned in an AI-generated code snippet is real or safe.

We’re doomed

Mearuu@kbin.melroy.org on 13 Apr 02:53 next collapse

I can’t imagine how a “black box” that is AI can ever be anything but a security risk. Compounding the problem are lazy developers that push code that they do not fully understand.

But it’s sTaTiStiCaLlY ReLeVaNt…

atzanteol@sh.itjust.works on 13 Apr 12:32 collapse

Generating dependencies is a huge weak point of ai right now. Version numbers are typically made up or very out of date at best. I just assume they’re wrong from the start now.