this post was submitted on 23 Feb 2026
63 points (88.0% liked)

Programming

25737 readers
608 users here now

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you're posting long videos try to add in some form of tldr for those who don't want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



founded 2 years ago
MODERATORS
 

AI-generated code is shipping to production without security review. The tools that generate the code don't audit it. The developers using the tools often lack the security knowledge to catch what the models miss. This is a growing blind spot in the software supply chain.

you are viewing a single comment's thread
view the rest of the comments
[–] rozodru@piefed.world 7 points 1 day ago

This really shouldn't be recent news to anyone. it's been like this since day one of vibe coding. It's all exploitable, none of it scales, and the "vibe coders" have zero clue how any of it works when it comes out the other end of the AI. none of them. and anyone that tells you otherwise is lying.

It's not a "growing blind spot" it's a blind spot that has always been there. And it happens with all companies even large ones like Amazon. look what happened with the AWS outages. hell you can even go on youtube and watch people who work at Amazon and you'll quickly realize these kids have no idea what the hell they're doing. I've followed one guy for the past year who documents his on calls with Amazon and this kid hasn't learned a single thing. He doesn't know what he's doing but will proudly tout how Amazon "helps" those that are laid off. The kid still gets tickets at 1am and has no clue how to fix the stuff and just hands it off to another team in the morning. he's been doing this for over a year!

So of course this stuff is going to go unchecked because the ones who are supposed to monitor it don't know what they're doing.