[HN Gopher] Security weaknesses of Copilot generated code in GitHub
       ___________________________________________________________________
        
       Security weaknesses of Copilot generated code in GitHub
        
       Author : belter
       Score  : 4 points
       Date   : 2023-10-04 19:19 UTC (3 hours ago)
        
 (HTM) web link (arxiv.org)
 (TXT) w3m dump (arxiv.org)
        
       | jncfhnb wrote:
       | Did they prompt it to consider security weaknesses?
        
       | belter wrote:
       | "...The results show that (1) 35.8% of Copilot generated code
       | snippets contain CWEs, and those issues are spread across
       | multiple languages, (2) the security weaknesses are diverse and
       | related to 42 different CWEs, in which CWE-78: OS Command
       | Injection, CWE-330: Use of Insufficiently Random Values, and
       | CWE-703: Improper Check or Handling of Exceptional Conditions
       | occurred the most frequently, and (3) among the 42 CWEs
       | identified, 11 of those belong to the currently recognized 2022
       | CWE Top-25. Our findings confirm that developers should be
       | careful when adding code generated by Copilot (and similar AI
       | code generation tools) and should also run appropriate security
       | checks as they accept the suggested code..."
        
       ___________________________________________________________________
       (page generated 2023-10-04 23:02 UTC)