By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Report: AI hallucinates 27% of upgrade recommendations for open source projects
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Report: AI hallucinates 27% of upgrade recommendations for open source projects
News

Report: AI hallucinates 27% of upgrade recommendations for open source projects

News Room
Last updated: 2026/01/29 at 12:02 PM
News Room Published 29 January 2026
Share
Report: AI hallucinates 27% of upgrade recommendations for open source projects
SHARE

Open source adoption is being accelerated by AI and automation, but developers must tread carefully to ensure they don’t introduce additional risks into their software supply chain.

Brian Fox, co-founder and CTO of Sonatype, explained that AI can accelerate good engineering, but can also scale mistakes faster, especially if it doesn’t have real-world data to draw from. For example, if a model doesn’t know which versions exist or which contain vulnerabilities, the model predicts and fills in, leading to upgrades to versions that don’t exist or recommendations that break builds.

In its 2026 State of Software Supply Chain report, Sonatype analyzed more than 1.2 million malicious packages, 1,700 vulnerability records, and 37,000 AI-driven upgrade recommendations. It turned out that AI models recommended more than 10,000 non-existent versions, which equates to a hallucination rate of 27.75%.

“On a large scale, that’s not funny. It’s an operational drag: wasted developer time, broken pipelines, and people losing faith in automation. And the scarier version is when AI recommends something that exists but shouldn’t be used because it’s vulnerable, malicious, or just outside your policy. AI can help, but only if it’s limited: grounded in real registry data, fed with current vulnerability and malware intelligence, and bound by the rules your organization actually follows. Otherwise, you have plausible automation made nonsense,” said Fox.

Recent research from IDC shows that developers accept 39% of AI-generated code without revision. “Combined with Sonatype’s findings, the data suggests that AI-driven recommendations benefit from a foundation in current supply chain intelligence and enforceable policies, so that increased development speed does not increase the attack surface by default,” said Katie Norton, research manager for DevSecOps and Software Supply Chain Security at IDC.

The report also shows that overall open source adoption increased 67% year-over-year across Maven Central, PyPl, npm, and NuGet, while open source malware grew 75% over the past year.

A large portion of the traffic came from repetitive pulls such as cold caches, ephemeral CI runners, and always clean builds. Additionally, the three largest cloud service providers generated more than 108 billion requests, or 86% of downloads.

“That’s not a million developers. That’s automation on an industrial scale,” Fox said. “I’m not saying ‘take it easy.’ I say: if you operate on a machine scale, act like it. Use sustainable caching. Configure proxies and mirrors correctly. Avoid pipeline patterns that re-fetch the world every time you rebuild. This is the kind of boring technology that keeps the commons healthy, produces less carbon and keeps your buildings reliable.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Why Google Calendar Sync Is Hard (and What Tokens Have to Do With It) | HackerNoon Why Google Calendar Sync Is Hard (and What Tokens Have to Do With It) | HackerNoon
Next Article Stock Market Today: Indexes Tank As Microsoft Sparks Wider Tech Sell-Off Stock Market Today: Indexes Tank As Microsoft Sparks Wider Tech Sell-Off
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Apple won’t sell you its in-store display accessories, but you can buy them here
Apple won’t sell you its in-store display accessories, but you can buy them here
News
Top 10+ Free and Paid Social Media Analytics Tools
Top 10+ Free and Paid Social Media Analytics Tools
Computing
Apple’s latest iOS update is causing havoc for Australian iPhone users
Apple’s latest iOS update is causing havoc for Australian iPhone users
Gadget
This powerful Satechi 100W charger is only .99!
This powerful Satechi 100W charger is only $14.99!
News

You Might also Like

Apple won’t sell you its in-store display accessories, but you can buy them here
News

Apple won’t sell you its in-store display accessories, but you can buy them here

2 Min Read
This powerful Satechi 100W charger is only .99!
News

This powerful Satechi 100W charger is only $14.99!

1 Min Read
Google’s AI helped me make bad Nintendo knockoffs
News

Google’s AI helped me make bad Nintendo knockoffs

11 Min Read
8 Underrated Pantry Staples That Chefs Swear By (and You Need)
News

8 Underrated Pantry Staples That Chefs Swear By (and You Need)

9 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?