5

GitHub Copilot update includes security vulnerability filtering

 1 year ago
source link: https://www.infoworld.com/article/3688269/github-copilot-update-includes-security-vulnerability-filtering.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

GitHub Copilot update includes security vulnerability filtering

GitHub says the controversial AI-assisted coding tool is now being used by more than 400 organizations to increase developer productivity and improve code quality.

By Paul Krill

Editor at Large,

InfoWorld | Feb 15, 2023 12:40 pm PST

padlock on a background of 0s and 1s

GitHub Copilot, the controversial tool that provides AI-assisted coding to developers, has been enhanced with algorithms to improve the quality and security of its coding suggestions.

Enhancements unveiled February 14 include an update to the underlying OpenAI Codex AI model to support large-scale improvements to code quality suggestions. The time required to deliver suggestions has also been reduced. These enhancements are available for both Copilot for individuals and Copilot for Businesses.

Additionally, AI-based vulnerability filtering in Copilot now blocks insecure coding patterns in real time. Common vulnerable coding patterns that are targeted include hard-coded credentials, path injections, and SQL injections. Vulnerable patterns even can be detected in incomplete fragments, GitHub said.

An AI pair programming tool trained using code from public repositories, Copilot offers auto-complete-style suggestions in a variety of programming languages. Copilot can be accessed via extensions to Visual Studio Code, Visual Studio, Neovim, and the JetBrains suite of IDEs. Users can sign up for a free trial of Copilot at Github.com.

GitHub this week also announced the general availability of Github Copilot for Business for all enterprises, even those that do not use GitHub. This announcement follows a beta phase that began in December. Businesses can sign up for Copilot and immediately assign seats. Also featured in GitHub Copilot for Businesses is VPN proxy support, so it is possible to use Copilot in any working environment.

Since its introduction in June 2021, Copilot has come under fire, with questions raised about the propriety of using publicly available code to train the AI. These concerns prompted a lawsuit and protests from the Free Software Foundation. But GitHub said this week that more than 400 organizations already are using Copilot, and that the tool is helping developers code faster.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK