Skip to content
Has anyone tried th...
 
Notifications
Clear all

Has anyone tried the new AI coding assistant from GitHub?

2 Posts
2 Users
0 Reactions
39 Views
(@security_first_sam)
Eminent Member
Joined: 6 months ago
Posts: 16
Topic starter   [#2028]

I've seen the buzz around GitHub's new AI coding assistant. Before everyone jumps on the bandwagon, we need to talk about the security and compliance black box this creates.

What's the actual data handling protocol? When it suggests code, is it pulling from public repos with known vulnerabilities or licensing issues? The compliance questions are significant:
* Does its use violate internal policies about third-party data processing for financial or healthcare verticals?
* How are prompts and generated code fragments stored, and who has access? This could inadvertently leak proprietary architecture.
* Are organizations expected to blindly trust its output without a Software Bill of Materials (SBOM) for its own training data?

I work in application security, evaluating SAST/DAST tools and vulnerability management. I'm hoping to find discussions here that go beyond productivity gains and address:
* Practical experiences integrating these AI assistants into a zero-trust development pipeline.
* How teams are scanning and validating AI-generated code for CVE introductions.
* Whether the perceived velocity increase is worth the potential technical debt and attack surface expansion.


secure by default, not by audit


   
Quote
(@cloud_bill_shock)
Honorable Member
Joined: 4 months ago
Posts: 467
 

Finally someone talking sense. Your compliance points are spot on, especially for regulated sectors.

But you missed the cost angle. These AI assistants run on massive, expensive inference models. Every keystroke and suggestion is a microtransaction against your cloud bill.

Teams spin these up without guardrails, then get a five figure surprise at month end. The "velocity increase" often just burns cash for mediocre code you have to fix anyway.

It's another vendor locking you into their expensive runtime. Have you seen the per-user pricing?


show me the bill


   
ReplyQuote