Exactly and my point is, that, Trivy checks the code for you, so you don't have to lol
On Thursday, June 25, 2026 at 6:12:27 AM UTC brainman wrote: > Thanks for explaining. > > But I do not see any difference between AI and manually written code. > > If you OK to take risk, then security does not matter. > > If you are not prepared to take risk, then you need to check code you > import. > > It is always been this way. > > Alex > > On Thursday, 25 June 2026 at 10:19:17 UTC+10 Cheikh Seck wrote: > >> When you start a project from an agent (ie: Claude, Codex) it tends to >> import old packages. I've experienced this while working for a smut website >> a few months back and most recently with Godex: where Trivy found 15 >> critical vulnerabilities. The idea I'm trying to convey is that LLMs may >> suggest packages while ignoring the fact that they may have been >> compromised since it was trained. Does that make sense? >> >> On Wednesday, June 24, 2026 at 9:33:58 PM UTC brainman wrote: >> >>> Cheikh, >>> >>> What problem are you trying to solve? >>> >>> You can still write your program yourself and not import crappy packages. >>> >>> Alex >>> >>> On Wednesday, 24 June 2026 at 19:41:57 UTC+10 Cheikh Seck wrote: >>> >>>> Key take-away from this article is that LLMs don't make the best >>>> judgement, but rather the average judgement. We spent months worrying >>>> about >>>> LLMs training on our code, but it turns out our code was cr*p all along :D >>>> >>>> On Wednesday, June 24, 2026 at 9:01:25 AM UTC Cheikh Seck wrote: >>>> >>>>> On Wednesday, June 24, 2026 at 8:57:20 AM UTC Cheikh Seck wrote: >>>>> >>>>>> I had Lite Agent (https://liteagent.cloud) compare Github commits >>>>>> before 2024 ( approximate time of pre-agentic AI adoption). The findings >>>>>> were a drastic increase in LoC. >>>>>> >>>>>> On Wednesday, June 24, 2026 at 8:50:02 AM UTC Stephen Illingworth >>>>>> wrote: >>>>>> >>>>>>> Where does the 60-80% figure come from? >>>>>>> On Wednesday, 24 June 2026 at 09:45:30 UTC+1 Cheikh Seck wrote: >>>>>>> >>>>>>>> Hi gophers, >>>>>>>> >>>>>>>> I've been thinking about how AI code generation changes our >>>>>>>> security assumptions. >>>>>>>> >>>>>>>> In 2026, a typical Go service has 60-80% AI-generated code. The >>>>>>>> dependency tree isn't curated by humans anymore - it's assembled by >>>>>>>> LLMs >>>>>>>> pulling from outdated training data. >>>>>>>> >>>>>>>> This means we need new security standards. Manual review isn't >>>>>>>> enough when you didn't write the imports. >>>>>>>> >>>>>>>> I just published a practical walkthrough showing how to implement >>>>>>>> one: automated security scanning with Trivy that blocks CVEs on every >>>>>>>> PR. >>>>>>>> Takes 5 minutes to set up. >>>>>>>> >>>>>>>> Article: https://medium.com/p/d91605771b04 >>>>>>>> >>>>>>>> Would love feedback from the community on: >>>>>>>> 1. Is this the right approach for AI-era security? >>>>>>>> 2. What other standards do we need to establish? >>>>>>>> >>>>>>>> Thanks, >>>>>>>> Cheikh >>>>>>> >>>>>>> -- You received this message because you are subscribed to the Google Groups "golang-nuts" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/d/msgid/golang-nuts/4167b81b-173a-4e16-9f55-1199887fb017n%40googlegroups.com.
