
“In March, we saw 55 reports coming from the community. In April, that went to 112. April is also when we finally got access to those frontier models and started doing internal scanning, and our internal scans gave us another 370 internal reports.” Michael Minella on the Spring Team.
The historical baseline was about seven a month. Finding the bugs is the easy part now; writing a fix you can put into a few million running applications is not. Ryan Morgan:
“For our most recent set of CVE patches, every single one of them was handwritten. AI helped identify and validate the issues, but the actual code itself was written directly by humans.”
And what that does downstream:
“The biggest change that I’ve seen is people have gotten away from trying to analyze piece by piece. They’re just patching and getting up to the latest across the board.”
A patch a day only helps if you can take a patch a day. There’s a lot more in the piece from Carly Page: “A tidal wave”: AI is flooding open source security teams.
Also:
(1) I talked with Ryan and Michael (interviewed in the piece) and my colleague Cora on this topic last month. There’s a lot more detail on how the Spring team has been working on making sure everything is secure. Check out the video:
(2) Also, see more on the support options for Spring for all of this.
Leave a Reply