The State of Generative AI in Software Development: Insights from Literature and a Developer Survey
2026-03-19T08:51:52Z•2cdd9b0113ac5d0e8766922d5a86c9360e6a9aa8822c5205c0c58c07fc3f0dc3
NVDcoding-agentsdataset-biasfaithfulness-lossformal-specificationsgenerative-aiintent-formalizationml-securityml-service-misuseprojectguardsecurity-patch-detectionsigstoresoftware-signingsoftware-supply-chainspecification-trackingvulnerability-detection
What happened
Collection of recent software-engineering papers with multiple security-relevant findings. Key points: (1) Identity-based software signing ecosystems (Sigstore, OpenPubKey, Vault, Keyfactor, Notary v2) show persistent usability friction in verification, policy/configuration, and integration that can lead to skipped verification and weakened supply-chain integrity. (2) Models trained on NVD-linked security patches perform poorly on in-the-wild security-commit detection (F1 drops up to ~90%), indicating dataset bias and risking missed vulnerability discovery; mixing NVD with a small manually-cur
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arxiv_cs_se
- Record identifier
- 2cdd9b0113ac5d0e8766922d5a86c9360e6a9aa8822c5205c0c58c07fc3f0dc3
- Enrichment time
- 2026-03-19T08:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.