The State of Generative AI in Software Development: Insights from Literature and a Developer Survey

2026-03-19T08:51:52Z2cdd9b0113ac5d0e8766922d5a86c9360e6a9aa8822c5205c0c58c07fc3f0dc3
NVDcoding-agentsdataset-biasfaithfulness-lossformal-specificationsgenerative-aiintent-formalizationml-securityml-service-misuseprojectguardsecurity-patch-detectionsigstoresoftware-signingsoftware-supply-chainspecification-trackingvulnerability-detection

What happened

Collection of recent software-engineering papers with multiple security-relevant findings. Key points: (1) Identity-based software signing ecosystems (Sigstore, OpenPubKey, Vault, Keyfactor, Notary v2) show persistent usability friction in verification, policy/configuration, and integration that can lead to skipped verification and weakened supply-chain integrity. (2) Models trained on NVD-linked security patches perform poorly on in-the-wild security-commit detection (F1 drops up to ~90%), indicating dataset bias and risking missed vulnerability discovery; mixing NVD with a small manually-cur

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arxiv_cs_se
Record identifier
2cdd9b0113ac5d0e8766922d5a86c9360e6a9aa8822c5205c0c58c07fc3f0dc3
Enrichment time
2026-03-19T08:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.