Exactly and my point is, that, Trivy checks the code for you, so you don't 
have to lol

On Thursday, June 25, 2026 at 6:12:27 AM UTC brainman wrote:

> Thanks for explaining.
>
> But I do not see any difference between AI and manually written code.
>
> If you OK to take risk, then security does not matter.
>
> If you are not prepared to take risk, then you need to check code you 
> import.
>
> It is always been this way.
>
> Alex
>
> On Thursday, 25 June 2026 at 10:19:17 UTC+10 Cheikh Seck wrote:
>
>> When you start a project from an agent (ie: Claude, Codex) it tends to 
>> import old packages. I've experienced this while working for a smut website 
>> a few months back and most recently with Godex: where Trivy found 15 
>> critical vulnerabilities. The idea I'm trying to convey is that LLMs may 
>> suggest packages while ignoring the fact that they may have been 
>> compromised since it was trained. Does that make sense?
>>
>> On Wednesday, June 24, 2026 at 9:33:58 PM UTC brainman wrote:
>>
>>> Cheikh,
>>>
>>> What problem are you trying to solve?
>>>
>>> You can still write your program yourself and not import crappy packages.
>>>
>>> Alex
>>>
>>> On Wednesday, 24 June 2026 at 19:41:57 UTC+10 Cheikh Seck wrote:
>>>
>>>> Key take-away from this article is that LLMs don't make the best 
>>>> judgement, but rather the average judgement. We spent months worrying 
>>>> about 
>>>> LLMs training on our code, but it turns out our code was cr*p all along :D
>>>>
>>>> On Wednesday, June 24, 2026 at 9:01:25 AM UTC Cheikh Seck wrote:
>>>>
>>>>> On Wednesday, June 24, 2026 at 8:57:20 AM UTC Cheikh Seck wrote:
>>>>>
>>>>>> I had Lite Agent (https://liteagent.cloud) compare Github commits 
>>>>>> before 2024 ( approximate time of pre-agentic AI adoption). The findings 
>>>>>> were a drastic increase in LoC.
>>>>>>
>>>>>> On Wednesday, June 24, 2026 at 8:50:02 AM UTC Stephen Illingworth 
>>>>>> wrote:
>>>>>>
>>>>>>> Where does the 60-80% figure come from?
>>>>>>> On Wednesday, 24 June 2026 at 09:45:30 UTC+1 Cheikh Seck wrote:
>>>>>>>
>>>>>>>> Hi gophers,
>>>>>>>>
>>>>>>>> I've been thinking about how AI code generation changes our 
>>>>>>>> security assumptions.
>>>>>>>>
>>>>>>>> In 2026, a typical Go service has 60-80% AI-generated code. The 
>>>>>>>> dependency tree isn't curated by humans anymore - it's assembled by 
>>>>>>>> LLMs 
>>>>>>>> pulling from outdated training data.
>>>>>>>>
>>>>>>>> This means we need new security standards. Manual review isn't 
>>>>>>>> enough when you didn't write the imports.
>>>>>>>>
>>>>>>>> I just published a practical walkthrough showing how to implement 
>>>>>>>> one: automated security scanning with Trivy that blocks CVEs on every 
>>>>>>>> PR. 
>>>>>>>> Takes 5 minutes to set up.
>>>>>>>>
>>>>>>>> Article: https://medium.com/p/d91605771b04
>>>>>>>>
>>>>>>>> Would love feedback from the community on:
>>>>>>>> 1. Is this the right approach for AI-era security?
>>>>>>>> 2. What other standards do we need to establish?
>>>>>>>>
>>>>>>>> Thanks,
>>>>>>>> Cheikh
>>>>>>>
>>>>>>>

-- 
You received this message because you are subscribed to the Google Groups 
"golang-nuts" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/d/msgid/golang-nuts/4167b81b-173a-4e16-9f55-1199887fb017n%40googlegroups.com.

Reply via email to