Nemeski@lemm.ee to Cybersecurity@sh.itjust.worksEnglish · 7 days agoAI-hallucinated code dependencies become new supply chain riskwww.bleepingcomputer.comexternal-linkmessage-square3fedilinkarrow-up12arrow-down10cross-posted to: [email protected]
arrow-up12arrow-down1external-linkAI-hallucinated code dependencies become new supply chain riskwww.bleepingcomputer.comNemeski@lemm.ee to Cybersecurity@sh.itjust.worksEnglish · 7 days agomessage-square3fedilinkcross-posted to: [email protected]
minus-squarecan@sh.itjust.workslinkfedilinkEnglisharrow-up1·7 days ago The only way to mitigate this risk is to verify package names manually and never assume a package mentioned in an AI-generated code snippet is real or safe. We’re doomed
We’re doomed