Skip to main content
SnykCustomer feedback

A Snyk user reports being overwhelmed by a tripled CVE backlog after their development team started using AI to write code, finding the volume of findings unmanageable.

What happened

Post: "How are you cutting a CVE backlog that exploded once AI wrote half the code?"

Source

RedditSep 23, 2026By u/Mangwe_Tanser

r/devsecops

How are you cutting a CVE backlog that exploded once AI wrote half the code?

upvotes
26
comments
27

Post

Highlighted: the lines this signal was extracted from

Half our code is Copilot and Claude now and as a result the CVE backlog has tripled. Trivy, Snyk and Dependabot all throwing piles of new findings, most of them in generated code and dependencies nothing on our side ever calls. We already sort by KEV and EPSS and whether it is internet facing. That held up until the AI volume buried it, now even the KEV-filtered list is too long to clear in a sprint. Beyond KEV and EPSS, does reachability really cut the list and only flagging a CVE when the vulnerable code sits on a live path or just move the noise somewhere else?

reddit.com/r/devsecops/comments/1wobjbb/how_are_you_cutting_a_cve_bac...Read the full source

Comments on the post

5 of 27 comments
  • “I think there's another way to view this issue. Trying to cut-down backlogs by throwing more tooling seems like such a brute force approach to me. Having been a dev for most of my career, I can tell you, we're not known for our security first mindset (I have a healthy one now!). I think devs need the proper guidance - and their own tools - to learn the "why". Very few have been involved in inc”

    u/Huge-Ambition46568 points · Sep 23, 2026View

  • “Disclosure: I work for Endor Labs. We think reachability is pretty important. I'm personally coming to the opinion that the operational imapcts of the increased CVE discoveries will be as big a problem as the actual secuirty risk. Short answer: yes. If you can reliably know if you are/aren't using the particular function in a library that has a vulnerability, then you can filter/de-prioritize”

    u/endor_robert3 points · Sep 23, 2026View

  • “We have tooling setup that allows us to easily upgrade dependencies, vulnerable or not. It does it through first party refactoring to work with the new/upgraded libraries.....pretty much auto-refactoring, minimal dev lift”

    u/zperdy2 points · Sep 23, 2026View

  • “the thing that actually shrinks that queue is remediation speed, not more sorting, so it's worth leaning on vendors who backport the fix into your current version instead of forcing a major bump for every finding. with cisa's tighter remediation timelines the backlog math only gets worse if each fix is a breaking upgrade. we tried aikido for patched oss libraries and weren't happy with the variety”

    u/ILoveAppSec2 points · Sep 24, 2026View

  • “La alcanzabilidad puede ayudar bastante, pero no la tomaría como una solución mágica. Si una dependencia vulnerable ni siquiera se usa en una ruta activa, yo la pondría mucho más abajo. También revisaría si el fallo realmente puede afectar a la aplicación y si existe una forma realista de explotarlo.”

    u/AgileCranberry87852 points · Sep 24, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/devsecops

Companies

  • TrivyAlso named
  • DependabotAlso named
  • GitHubAlso named
  • AnthropicAlso named

The full record

From the Signal API record

Numbers

Mentions
1

Details

Timing
Ongoing state
Category
Usability
Virality
High
Post kind
Text
Prominence
Core
Company's role
Vendor

Topics and mentions

Topics

  • vulnerability management
  • reporting
  • sca
  • cve
  • ai

Extraction

Sentiment
Negative
Detected
Sep 23, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for Snyk and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Snyk this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/797f5129-be98-53c4-a74e-41c6d42495ea returns this record as JSON. POST /v1/companies/enrich returns every signal for snyk.io.

{
  "signal_id": "797f5129-be98-53c4-a74e-41c6d42495ea",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-09-23T16:55:09+00:00",
  "company": {
    "name": "Snyk",
    "domain": "snyk.io"
  },
  "data": {
    "nsfw": false,
    "stage": "none",
    "awards": 0,
    "timing": "ongoing_state",
    "topics": [
      "sca",
      "cve",
      "vulnerability management",
      "reporting",
      "ai"
    ],
    "post_id": "1wobjbb",
    "summary": "A Snyk user reports being overwhelmed by a tripled CVE backlog after their development team started using AI to write code, finding the volume of findings unmanageable.",
    "category": "usability",
    "comments": [
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wobjbb/comment/pbm8161/",
        "depth": 0,
        "score": 8,
        "author": "Huge-Ambition4656",
        "excerpt": "I think there's another way to view this issue. Trying to cut-down backlogs by throwing more tooling seems like such a brute force approach to me.\n\n Having been a dev for most of my career, I can tell you, we're not known for our security first mindset (I have a healthy one now!).\n\n I think devs need the proper guidance - and their own tools - to learn the \"why\". Very few have been involved in inc",
        "posted_at": "2026-09-23T18:29:42.000Z",
        "author_url": "https://www.reddit.com/user/Huge-Ambition4656/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wobjbb/comment/pblq4u0/",
        "depth": 0,
        "score": 3,
        "author": "endor_robert",
        "excerpt": "Disclosure: I work for Endor Labs. We think reachability is pretty important. I'm personally coming to the opinion that the operational imapcts of the increased CVE discoveries will be as big a problem as the actual secuirty risk.\n\n Short answer: yes.\n\n If you can reliably know if you are/aren't using the particular function in a library that has a vulnerability, then you can filter/de-prioritize",
        "posted_at": "2026-09-23T17:15:24.000Z",
        "author_url": "https://www.reddit.com/user/endor_robert/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wobjbb/comment/pbmhspj/",
        "depth": 0,
        "score": 2,
        "author": "zperdy",
        "excerpt": "We have tooling setup that allows us to easily upgrade dependencies, vulnerable or not. It does it through first party refactoring to work with the new/upgraded libraries.....pretty much auto-refactoring, minimal dev lift",
        "posted_at": "2026-09-23T19:10:56.000Z",
        "author_url": "https://www.reddit.com/user/zperdy/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wobjbb/comment/pbp5nqj/",
        "depth": 0,
        "score": 2,
        "author": "ILoveAppSec",
        "excerpt": "the thing that actually shrinks that queue is remediation speed, not more sorting, so it's worth leaning on vendors who backport the fix into your current version instead of forcing a major bump for every finding. with cisa's tighter remediation timelines the backlog math only gets worse if each fix is a breaking upgrade. we tried aikido for patched oss libraries and weren't happy with the variety",
        "posted_at": "2026-09-24T03:21:41.000Z",
        "author_url": "https://www.reddit.com/user/ILoveAppSec/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wobjbb/comment/pbq3gxf/",
        "depth": 0,
        "score": 2,
        "author": "AgileCranberry8785",
        "excerpt": "La alcanzabilidad puede ayudar bastante, pero no la tomaría como una solución mágica. Si una dependencia vulnerable ni siquiera se usa en una ruta activa, yo la pondría mucho más abajo. También revisaría si el fallo realmente puede afectar a la aplicación y si existe una forma realista de explotarlo.",
        "posted_at": "2026-09-24T07:35:58.000Z",
        "author_url": "https://www.reddit.com/user/AgileCranberry8785/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wobjbb/comment/pbrxyiq/",
        "depth": 0,
        "score": 2,
        "author": "raisputin",
        "excerpt": "Copilot is trash",
        "posted_at": "2026-09-24T14:38:52.000Z",
        "author_url": "https://www.reddit.com/user/raisputin/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wobjbb/comment/pbsuwnj/",
        "depth": 0,
        "score": 2,
        "author": "GeneviaCedotal",
        "excerpt": "some packages only show up during tests or builds and never run in prod. kindly wory less abt those and spend more time on CVEs in code people actually use. How much of your backlog is coming from dev dependencies right now?",
        "posted_at": "2026-09-24T16:57:52.000Z",
        "author_url": "https://www.reddit.com/user/GeneviaCedotal/"
      },
      {
        "url": "https://www.reddit.com/r/devsecops/comments/1wobjbb/comment/pbszud8/",
        "depth": 0,
        "score": 2,
        "author": "GayaniTupai75",
        "excerpt": "Same thing hit us once most of the code was AI written, backlog blew up on the deps and on our own code both.\n\n Reachability sorted out the dependency side ok, cut all the stuff sitting in packages we dont even call. Didnt really touch our own AI code though.\n\n We just use checkmarx one for it now and it does the sast and the sca together so everything lands in one queue and we dropped the second",
        "posted_at": "2026-09-24T17:18:40.000Z",
        "author_url": "https://www.reddit.com/user/GayaniTupai75/"
      }
    ],
    "evidence": [
      "[post] Trivy, Snyk and Dependabot all throwing piles of new findings, most of them in generated code and dependencies nothing on our side ever calls.",
      "[post] the CVE backlog has tripled."
    ],
    "virality": "high",
    "post_date": "2026-09-23T16:55:09.000Z",
    "post_kind": "text",
    "post_text": "Half our code is Copilot and Claude now and as a result the CVE backlog has tripled. Trivy, Snyk and Dependabot all throwing piles of new findings, most of them in generated code and dependencies nothing on our side ever calls.\n\nWe already sort by KEV and EPSS and whether it is internet facing. That held up until the AI volume buried it, now even the KEV-filtered list is too long to clear in a sprint.\n\nBeyond KEV and EPSS, does reachability really cut the list and only flagging a CVE when the vulnerable code sits on a live path or just move the noise somewhere else?",
    "sentiment": "negative",
    "subreddit": "devsecops",
    "post_title": "How are you cutting a CVE backlog that exploded once AI wrote half the code?",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/devsecops/comments/1wobjbb/how_are_you_cutting_a_cve_backlog_that_exploded/",
    "entity_role": "vendor",
    "post_author": "Mangwe_Tanser",
    "upvote_ratio": 0.9642857142857143,
    "mention_count": 1,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/devsecops/",
    "total_upvotes": 26,
    "comments_total": 27,
    "total_comments": 27,
    "other_companies": [
      {
        "name": "Trivy",
        "role": "alternative",
        "domain": "trivy.dev"
      },
      {
        "name": "Dependabot",
        "role": "alternative",
        "domain": "github.com"
      },
      {
        "name": "GitHub",
        "role": "partner",
        "domain": "github.com"
      },
      {
        "name": "Anthropic",
        "role": "partner",
        "domain": "anthropic.com"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/Mangwe_Tanser/",
    "signal_category": "feedback",
    "comments_included": 16
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.