|
|
|
|
|
by waynesoftware
1767 days ago
|
|
Summary: CONCLUSIONS AND FUTURE WORK There is no question that next-generation ‘auto-complete’
tools like GitHub Copilot will increase the productivity of
software developers. However, while Copilot can rapidly
generate prodigious amounts of code, our conclusions reveal
that developers should remain vigilant (‘awake’) when using
Copilot as a co-pilot. Ideally, Copilot should be paired
with appropriate security-aware tooling during both training
and generation to minimize the risk of introducing security vulnerabilities. While our study provides new insights into
its behavior in response to security-relevant scenarios, future work should investigate other aspects, including adversarial approaches for security-enhanced training |
|