r/devsecops
How are you cutting a CVE backlog that exploded once AI wrote half the code?
- upvotes
- 26
- comments
- 27
Post
Highlighted: the lines this signal was extracted from
Half our code is Copilot and Claude now and as a result the CVE backlog has tripled. Trivy, Snyk and Dependabot all throwing piles of new findings, most of them in generated code and dependencies nothing on our side ever calls. We already sort by KEV and EPSS and whether it is internet facing. That held up until the AI volume buried it, now even the KEV-filtered list is too long to clear in a sprint. Beyond KEV and EPSS, does reachability really cut the list and only flagging a CVE when the vulnerable code sits on a live path or just move the noise somewhere else?