惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

AWS News Blog
AWS News Blog
T
Tenable Blog
Project Zero
Project Zero
T
The Exploit Database - CXSecurity.com
L
LINUX DO - 热门话题
T
Threat Research - Cisco Blogs
T
Threatpost
Security Latest
Security Latest
C
Cisco Blogs
L
Lohrmann on Cybersecurity
S
Security @ Cisco Blogs
Google Online Security Blog
Google Online Security Blog
NISL@THU
NISL@THU
AI
AI
V
Vulnerabilities – Threatpost
Google DeepMind News
Google DeepMind News
C
Cyber Attacks, Cyber Crime and Cyber Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
The Last Watchdog
The Last Watchdog
G
GRAHAM CLULEY
Cloudbric
Cloudbric
H
Hackread – Cybersecurity News, Data Breaches, AI and More
H
Hacker News: Front Page
U
Unit 42
A
Arctic Wolf
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
MyScale Blog
MyScale Blog
O
OpenAI News
Scott Helme
Scott Helme
V2EX - 技术
V2EX - 技术
P
Proofpoint News Feed
博客园 - 叶小钗
Hugging Face - Blog
Hugging Face - Blog
云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Cyberwarzone
Cyberwarzone
博客园 - 【当耐特】
H
Heimdal Security Blog
S
Schneier on Security
阮一峰的网络日志
阮一峰的网络日志
Help Net Security
Help Net Security
D
DataBreaches.Net
Y
Y Combinator Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
TaoSecurity Blog
TaoSecurity Blog
K
Kaspersky official blog
N
News and Events Feed by Topic
WordPress大学
WordPress大学
P
Palo Alto Networks Blog

Press Releases

Sonatype Research Labs Marks 15 Years of Open Source Intelligence Sonatype Named a Leader in the 2026 Gartner® Magic Quadrant™ Sonatype Strengthens Leadership Team for AI-Driven Growth Sonatype Firewall Extends Malicious Package Protection Sonatype and Package Registry Leaders Unite on OS Sustainability Sonatype Releases Q1 2026 Open Source Malware Index Sonatype Research Reveals Open Source Malware Grows 75% Sonatype Introduces Guide for Secure Agentic Development CVE Program Leaves Vulnerabilities Unscored | Sonatype Sonatype Unveils Nexus One: An AI-Native DevSecOps Platform Sonatype Grand Opening of India Innovation Hub in Hyderabad Announcing 2025 Elevate Award Winners & Finalists | Sonatype Open Source Malware Surges in Q3 as Attackers Target Dependencies Sonatype Named Visionary in 2025 Gartner® Magic Quadrant™ for AST Sonatype Launches Nexus Repository Cloud in the AI Era | Sonatype
AI Grounded in Intelligence Delivers Safer Outcomes | Sonatype
2026-03-24 · via Press Releases

Across nearly 37,000 software upgrade recommendations, AI grounded in real-time intelligence delivered safer outcomes than larger models operating without live context

Fulton, Md. – March 24, 2025 Sonatype®, the leader in AI-driven DevSecOps, today unveiled new research showing that larger-scale AI models alone do not produce the safest software dependency recommendations. In a study of roughly 37,000 open source upgrade recommendations, models grounded in real-time software intelligence reduced retained Critical and High risk beyond what larger ungrounded models from Anthropic, Google, and OpenAI could achieve on their own.

Sonatype found that newer, bigger models with improved reasoning and speed became more cautious, increasingly recommending “no change” to an open source component rather than a safer upgrade path. Although that restraint reduced hallucinations, it often left meaningful Critical and High vulnerability exposure in place.

The findings show that safer AI-assisted software dependency decisions require more than model scale alone. They require real-time software intelligence that helps models validate package availability, assess upgrade paths, account for known vulnerabilities, and reduce the tradeoff between remediation and disruption. Key findings include:

  • Frontier models are improving, but hallucinations persist: Even the best ungrounded models, which lack real-time intelligence, still fabricated roughly 1 in 16 dependency recommendations.
  • Greater restraint still left meaningful risk exposure: Newer models increasingly recommended “no change,” with the most cautious models still carrying roughly 800 to 900 Critical and High vulnerabilities.
  • Grounded intelligence outperformed standalone LLMs on security outcomes: Across Maven Central, npm, and PyPI, Sonatype’s Hybrid approach, which selects the most secure upgrade path, delivered 269% to 309% mean security score improvement, versus only 24% to 68% for the best LLM in each ecosystem.
  • Real-time intelligence mattered more than model size alone: A small grounded model resulted in significantly lower Critical and High risk at up to 71x lower cost than frontier models.

"Larger models may be improving at reasoning, but dependency management is not a reasoning problem alone — it is a data problem. If a model does not know your actual environment, current vulnerability data, and the policies you operate under, it is just making educated guesses,” said Brian Fox, Co-founder and CTO at Sonatype. “Grounding AI in that reality is what makes its recommendations useful, credible, and safe for enterprise use.”

This study builds on the From Guesswork to Grounded chapter of the 2026 State of the Software Supply Chain® report. The study evaluated roughly 37,000 open source upgrade recommendations across Maven Central, PyPI, npm, and NuGet, comparing ungrounded frontier models with approaches augmented by real-time software intelligence.

Sonatype Guide, powered by this real-time intelligence, helps organizations identify safer open source upgrade paths, reduce avoidable risk, and limit unnecessary developer disruption from breaking changes or poor recommendations. By grounding AI in live software supply chain data, Sonatype helps teams operationalize AI-assisted remediation with greater safety and confidence.

To read the full study, Making AI Software Development Safe at Machine Scale, visit: https://www.sonatype.com/resources/research/making-ai-work-safely.

About Sonatype

Sonatype is the leader in AI-driven DevSecOps. As the maintainers of Maven Central and creators of Nexus Repository, Sonatype has spent two decades pioneering how the world manages and secures open source software — making Sonatype the trusted authority for modern software supply chains. With unmatched open source visibility and a unified product suite built for modern software development, Sonatype gives enterprises the intelligence and automated governance they need to harness the full potential of open source and AI. Sonatype handles the complexity behind the scenes: guiding component and model selection, blocking harmful malicious code, automating dependency and vulnerability management, and ensuring faster, more reliable builds — so developers spend more time on innovation and less time on remediation and rework. Trusted by more than 15 million developers, Sonatype helps power secure, modern software development at nearly 2,000 global organizations including 70% of the Fortune 100. To learn more about Sonatype, please visit www.sonatype.com.

Methodology

We analyzed direct dependencies from enterprise applications scanned between June and August 2025, using the same application sample as the original study and limiting the dataset to Maven, npm, PyPI, and NuGet, which produced roughly 37,000 unique package-version pairs and about 258,000 recommendations evaluated across seven frontier models from OpenAI, Anthropic, and Google. Each model received the same prompt, and every recommended version was checked against Sonatype’s package registry, with non-existent versions classified as hallucinations and same-version recommendations treated as inaction. Security outcomes were measured using Sonatype’s enriched severity scoring and deduplicated advisory counts, with hallucinated versions treated as no-ops because package managers would reject them in practice; Sonatype’s Hybrid strategy served as the benchmark throughout. We also tested whether real-time ecosystem intelligence matters more than model scale by evaluating GPT-5 Nano on a 397-component adversarial sample skewed toward known failure modes, using a single function-calling tool backed by Sonatype Guide’s version recommendation API and applying the same validation and security methodology.