2026
Peer-Reviewed Research
Security Vulnerabilities in AI-Generated Code: A Large-Scale Analysis of Public GitHub Repositories
Material CWE-mapped weaknesses were identified in the dataset.
- Security & Supply Chain
- AI-Assisted Development
Evidence note
A structured application-security verification standard containing concrete requirements for assessing technical security controls.
Why it matters. Lornets interpretation.
Security assurance should be based on evidence against relevant technical requirements rather than simply asking whether an application appears to address a list of common vulnerabilities.
This is the Lornets reading of the source, not a finding of the source itself.
Framework domains
Last verified 2026-08-11
2026
Peer-Reviewed Research
Material CWE-mapped weaknesses were identified in the dataset.
2022
Government Guidance
SSDF organises secure-development practices into a structured set of outcomes rather than prescribing one development methodology.
Current, revision underway
National Institute of Standards and Technology, SP 800-218, SSDF v1.1
2026
Government Guidance
The guidance uses assurance claims rather than treating high-level principles as self-evident.
UK National Cyber Security Centre