LLMs frequently specify library versions with known CVEs in generated code (36-56% of tasks), show low compatibility (20-63%), and converge on the same risky versions across models.
Title resolution pending
3 Pith papers cite this work. Polarity classification is still indexing.
citation-role summary
citation-polarity summary
fields
cs.SE 3years
2026 3roles
background 1polarities
background 1representative citing papers
No surveyed AI delivery platform emits by default a content-addressed identity of the model, instructions, tools, and runtime being deployed, and most attestation-adopting repositories declare a binding that cannot be checked on their release surface.
Empirical evaluation shows popular SBOM tools miss CIMs across languages, so security-grade SBOMs are not achievable under current definitions.
citing papers explorer
-
Correct Code, Vulnerable Dependencies: A Large Scale Measurement Study of LLM-Specified Library Versions
LLMs frequently specify library versions with known CVEs in generated code (36-56% of tasks), show low compatibility (20-63%), and converge on the same risky versions across models.
-
From Traceability to Justifiability: Accountability Structures in Agentic Software Engineering
No surveyed AI delivery platform emits by default a content-addressed identity of the model, instructions, tools, and runtime being deployed, and most attestation-adopting repositories declare a binding that cannot be checked on their release surface.
-
Poking Around in the Dark: Why a Shared Understanding of Components Matters
Empirical evaluation shows popular SBOM tools miss CIMs across languages, so security-grade SBOMs are not achievable under current definitions.