236
why, GitHub
(lemmy.ml)
Post funny things about programming here! (Or just rant about your favourite programming language.)
GitHub Advanced Security seems useful. AI has successfully found security vulnerabilities that would've otherwise gone undetected, and as a rule of thumb all security vulnerabilities need to be found and patched.
"AI" has also successfully found security vulnerabilities that don't exist.
Better a false positive than false negative, as long as people aren't submitting AI generated bug bounty reports to projects and hiding the fact they're AI.
People are submitting AI generated bug bounty reports to projects and are hiding the fact that they're AI.
EDIT: I probably should have linked this one.
My point was that those kinds of reports are useless, this kind of feature is only useful if experienced devs voluntarily use it.
I take it you're not the one triaging the subsequent slop. I am.
That's because the feature is being abused by others.
but you can check them off as work done for managers that don't understand it. lol