▲ | We Found Zero Low-Severity Bugs in 165 AI Code Reports. Zero(shamans.dev) | |||||||||||||||||||||||||||||||
15 points by dmonroy 2 days ago | 14 comments | ||||||||||||||||||||||||||||||||
▲ | lpapez 2 days ago | parent | next [-] | |||||||||||||||||||||||||||||||
What is the overall severity distribution, including human code? Based on the churn I have fixing security vulnerabilities reported by Snyk and Trivy, I have a feeling that issues have a tendency to be labeled mostly as HIGH or CRITICAL when they are assigned a CVE, for better or worse. | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
▲ | eqvinox a day ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||
I neither understand where the HN title line is coming from, nor what this report is trying to tell me. AI is introducing high severity bugs rather than low severity ones? That's… bad? Is this based on actual reports, or it's own analysis? Actual reports will have survivorship bias since higher severities are reported more actively and quicker… Anyway, I see numbers but no message. | ||||||||||||||||||||||||||||||||
▲ | TrinaryWorksToo 2 days ago | parent | prev | next [-] | |||||||||||||||||||||||||||||||
How do we know this isn't Survivorship Bias? Perhaps there aren't any low-severity bugs because they're all high severity? | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||
▲ | weare138 2 days ago | parent | prev [-] | |||||||||||||||||||||||||||||||
This is an ongoing longitudinal study with inherent reporting biases and coverage limitations. Well at least they're honest... | ||||||||||||||||||||||||||||||||
|