@aphedges @paulshryock We have high standards for code quality and that's not going to change. Tools to criticize our code and find things we missed despite repeatedly reviewing it ourselves are very useful. It's fine if most of the output is wrong because it finds actual issues.
Attackers are heavily using AI models to discover vulnerabilities and develop exploits. For example, Cellebrite is heavily using it including developing frameworks for reverse engineering and vulnerability discovery.
@aphedges @paulshryock AI models are being used on a much larger scale for discovering and fixing vulnerabilities in the Linux kernel, AOSP, Chromium and other projects used by GrapheneOS.
There's a massive increase in the number of vulnerabilities fixed in each Linux kernel release and many are severe issues:
https://www.phoronix.com/news/Linux-Kernel-CVEs-Nearly-2000
That increase is despite adding features slowly down a lot. A massive monolithic kernel written in a memory unsafe language is a bigger liability than ever.
The Linux Kernel Is Approaching 2,000 CVEs Per Release