←back to thread

1208 points jamesberthoty | 3 comments | | HN request time: 0.001s | source
1. whatever1 ◴[] No.45274665[source]
Isn’t this a good case for LLMs? Audit at compile time all of the dependencies?
replies(1): >>45274911 #
2. huem0n ◴[] No.45274911[source]
Please no, see

> Using CVE reports as a weapon

https://www.youtube.com/watch?v=GDdlRiThDeg

replies(1): >>45275872 #
3. whatever1 ◴[] No.45275872[source]
Oh you took it further, let the LLM take the wheel. I was just referring to the LLM raising a red flag during compilation. So worst case scenario it will just raise a false positive.