Using frontier models to find security problems in Spring Framework – a trickle turned into a tidal wave

Line chart titled Community Security Reports showing Spring open source community security advisories from mid-2025 through mid-2026, low single digits until early 2026, spiking to about 110 in spring 2026, then projected to stay elevated around 50 through July 2026.
Community security reports for Spring. From Broadcom’s Tanzu blog.

“In March, we saw 55 reports coming from the community. In April, that went to 112. April is also when we finally got access to those frontier models and started doing internal scanning, and our internal scans gave us another 370 internal reports.” Michael Minella on the Spring Team.

The historical baseline was about seven a month. Finding the bugs is the easy part now; writing a fix you can put into a few million running applications is not. Ryan Morgan:

“For our most recent set of CVE patches, every single one of them was handwritten. AI helped identify and validate the issues, but the actual code itself was written directly by humans.”

And what that does downstream:

“The biggest change that I’ve seen is people have gotten away from trying to analyze piece by piece. They’re just patching and getting up to the latest across the board.”

A patch a day only helps if you can take a patch a day. There’s a lot more in the piece from Carly Page: “A tidal wave”: AI is flooding open source security teams.

Also:

(1) I talked with Ryan and Michael (interviewed in the piece) and my colleague Cora on this topic last month. There’s a lot more detail on how the Spring team has been working on making sure everything is secure. Check out the video:

(2) Also, see more on the support options for Spring for all of this.

Comments

Leave a Reply

Discover more from Coté

Subscribe now to keep reading and get access to the full archive.

Continue reading