Close Menu
  • Home
  • AI
  • Big Data
  • Cloud Computing
  • iOS Development
  • IoT
  • IT/ Cybersecurity
  • Tech
    • Nanotechnology
    • Green Technology
    • Apple
    • Software Development
    • Software Engineering

Subscribe to Updates

Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

    What's Hot

    Single atoms of indium on hafnia enable superior CO2-based methanol synthesis

    March 3, 2026

    A Retrospective on Workload Security

    March 3, 2026

    New Apple Studio Display and Studio Display XDR Don’t Work With Intel Macs

    March 3, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Big Tee Tech Hub
    • Home
    • AI
    • Big Data
    • Cloud Computing
    • iOS Development
    • IoT
    • IT/ Cybersecurity
    • Tech
      • Nanotechnology
      • Green Technology
      • Apple
      • Software Development
      • Software Engineering
    Big Tee Tech Hub
    Home»Software Development»Report: AI hallucinates 27% of upgrade recommendations for open source projects
    Software Development

    Report: AI hallucinates 27% of upgrade recommendations for open source projects

    big tee tech hubBy big tee tech hubJanuary 29, 2026023 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Report: AI hallucinates 27% of upgrade recommendations for open source projects
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    pexels shvetsa 5711914pexels shvetsa 5711914

    Open-source adoption is being accelerated by AI and automation, but developers need to proceed with caution to ensure they’re not introducing extra risk into their software supply chain.

    Brian Fox, co-founder and CTO of Sonatype, explained that AI can accelerate good engineering, but it can also scale mistakes faster, especially if it doesn’t have real-world data to pull from. For example, if a model doesn’t know what versions exist or which ones have vulnerabilities, it predicts and fills in the blank, leading to upgrades to versions that don’t exist or recommendations that break builds.

    In its 2026 State of Software Supply Chain report, Sonatype analyzed over 1.2 million malicious packages, 1,700 vulnerability records, and 37,000 AI-driven upgrade recommendations. It found that AI models recommended over 10,000 non-existent versions, which is a 27.75% hallucination rate.

    “At scale, that’s not funny. It’s operational drag: wasted developer time, broken pipelines, and people losing trust in automation. And the scarier version is when AI recommends something that does exist, but shouldn’t be used, because it’s vulnerable, malicious, or simply outside your policy. AI can help, but only if it’s constrained: grounded in real registry data, fed current vulnerability and malware intelligence, and bound by the rules your organization actually follows. Otherwise, you’ve automated plausible nonsense,” Fox said.

    Recent research from IDC shows that developers accept 39% of AI-generated code without revision. “When paired with Sonatype’s findings, the data suggests that AI-driven recommendations benefit from grounding in current supply chain intelligence and enforceable policy, so that increased development velocity does not expand the attack surface by default,” said Katie Norton, research manager for DevSecOps and Software Supply Chain Security at IDC.

    The report also found that open-source adoption in general was up 67% year-over-year across Maven Central, PyPl, npm, and NuGet, while open-source malware grew 75% over the last year.

    A lot of the traffic came from repeat pulls like cold caches, ephemeral CI runners, and always-clean builds. Additionally, the top three cloud service providers generated over 108 billion requests, or 86% of downloads.

    “That’s not a million developers. That’s automation at an industrial scale,” Fox said. “I’m not saying ‘slow down.’ I’m saying: if you’re operating at machine scale, act like it. Use durable caching. Configure proxies and mirrors correctly. Avoid pipeline patterns that refetch the world every time you rebuild. This is the kind of boring engineering that keeps the commons healthy, produces less carbon, and keeps your builds reliable.”



    Source link

    hallucinates open Projects Recommendations Report source upgrade
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    tonirufai
    big tee tech hub
    • Website

    Related Posts

    How Modern Data Integration Supercharges Software Development

    March 3, 2026

    How to Build a Microsoft Office Add-in with JavaScript: Complete Overview

    March 2, 2026

    Report: Open source licensing conflicts hit an all-time high as organizations struggle to audit AI-generated code for IP risks

    March 2, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Single atoms of indium on hafnia enable superior CO2-based methanol synthesis

    March 3, 2026

    A Retrospective on Workload Security

    March 3, 2026

    New Apple Studio Display and Studio Display XDR Don’t Work With Intel Macs

    March 3, 2026

    How Modern Data Integration Supercharges Software Development

    March 3, 2026
    About Us
    About Us

    Welcome To big tee tech hub. Big tee tech hub is a Professional seo tools Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of seo tools, with a focus on dependability and tools. We’re working to turn our passion for seo tools into a booming online website. We hope you enjoy our seo tools as much as we enjoy offering them to you.

    Don't Miss!

    Single atoms of indium on hafnia enable superior CO2-based methanol synthesis

    March 3, 2026

    A Retrospective on Workload Security

    March 3, 2026

    Subscribe to Updates

    Get the latest technology news from Bigteetechhub about IT, Cybersecurity and Big Data.

      • About Us
      • Contact Us
      • Disclaimer
      • Privacy Policy
      • Terms and Conditions
      © 2026 bigteetechhub.All Right Reserved

      Type above and press Enter to search. Press Esc to cancel.