logoalt Hacker News

MangoToupeyesterday at 5:50 AM1 replyview on HN

As a corollary, it might also increase the surface of upstream supply-chain attacks (patched or not)

The package import thing seems like a red herring


Replies

Retr0idyesterday at 6:17 AM

It's going to be fun if someone finds a security vulnerability in a commonly-emitted-by-LLMs code pattern. That'll be a lot harder to remediate than "Update dependency xyz"

show 1 reply