←back to thread

1208 points jamesberthoty | 2 comments | | HN request time: 0.473s | source
Show context
whatever1 ◴[] No.45274665[source]
Isn’t this a good case for LLMs? Audit at compile time all of the dependencies?
replies(1): >>45274911 #
1. huem0n ◴[] No.45274911[source]
Please no, see

> Using CVE reports as a weapon

https://www.youtube.com/watch?v=GDdlRiThDeg

replies(1): >>45275872 #
2. whatever1 ◴[] No.45275872[source]
Oh you took it further, let the LLM take the wheel. I was just referring to the LLM raising a red flag during compilation. So worst case scenario it will just raise a false positive.