[HN Gopher] Security weaknesses of Copilot generated code in GitHub
___________________________________________________________________
Security weaknesses of Copilot generated code in GitHub
Author : belter
Score : 4 points
Date : 2023-10-04 19:19 UTC (3 hours ago)
(HTM) web link (arxiv.org)
(TXT) w3m dump (arxiv.org)
| jncfhnb wrote:
| Did they prompt it to consider security weaknesses?
| belter wrote:
| "...The results show that (1) 35.8% of Copilot generated code
| snippets contain CWEs, and those issues are spread across
| multiple languages, (2) the security weaknesses are diverse and
| related to 42 different CWEs, in which CWE-78: OS Command
| Injection, CWE-330: Use of Insufficiently Random Values, and
| CWE-703: Improper Check or Handling of Exceptional Conditions
| occurred the most frequently, and (3) among the 42 CWEs
| identified, 11 of those belong to the currently recognized 2022
| CWE Top-25. Our findings confirm that developers should be
| careful when adding code generated by Copilot (and similar AI
| code generation tools) and should also run appropriate security
| checks as they accept the suggested code..."
___________________________________________________________________
(page generated 2023-10-04 23:02 UTC)