


@geerlingguy and it's getting worse:
Today in InfoSec Job Security News: I was looking into an obvious ../.. vulnerability introduced into a major web framework today, and it was committed by username Claude on GitHub. Vibe coded, basically. So I started looking through Claude commits on GitHub, there’s over 2m of them and it’s about 5% of all open source code this month. https://github.com/search?q=author%3Aclaude&type=commits&s=author-date&o=desc As I looked through the code I saw the same class of vulns being introduced over, and over, again - several a minute.
@geerlingguy A lot of open source is also unmaintained. I can only imagine the horrors of low effort random forks all over the place :(
If you couldn’t have written it yourself. Don’t use AI. If you can’t read and understand the code (and architecture) that the AI generated. Delete it and learn and write it yourself.
That’s my take. :)
@geerlingguy #OpenSource is in big trouble: https://malus.sh