Skip to content

What AI code review misses: SSRF and more

zeroquarry.com
1 pointeskibars1 comment
On HN

Comments

Author here. I built ZeroQuarry, and I was considering deploying an open source link shortener or using a SaaS one. I googled around and then found iShortn, so ran the iShortn scan with it.

I found a bunch of vulnerabilities, which I sent to the maintainer and have now been patched, but some of the most interesting ones I found were that many of these vulnerabilities were actually crafted by (or at least reviewed by) CodeRabbit.

I think there are a lot of reasons to use AI code review tools these days, and no problem with CodeRabbit, but one of the things I've found interesting is a discussion from investors and potential customers about "why would I use a security code reviewer when I have an AI code reviewer in place already". I thought some of the examples here may be interesting for others.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.