← Back to context

Comment by markasoftware

4 days ago

Since AISLE reported 29 issues but only 6 warranted a CVE, and all the found CVEs were "low" severity, this makes me wonder if AISLE simply is tuned for a higher false positive rate than the anthropic and openai tools (which may have found the same 6 issues and decided not to report them)

As far as I understand it, the other efforts have not reported most of their findings to upstream developers, focusing on critical findings only.

This is understandable because upstream interactions at scale are difficult.

  • In the case of big projects like curl the interaction seems a bit more complete. E.g. There are some other blog posts about how the engagements and reviews worked which go decently beyond a pre-filtered dump of high severity CVE claims appearing out of the blue.