By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Report: AI hallucinates 27% of upgrade recommendations for open source projects
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Report: AI hallucinates 27% of upgrade recommendations for open source projects
News

Report: AI hallucinates 27% of upgrade recommendations for open source projects

News Room
Last updated: 2026/01/29 at 12:02 PM
News Room Published 29 January 2026
Share
Report: AI hallucinates 27% of upgrade recommendations for open source projects
SHARE

Open source adoption is being accelerated by AI and automation, but developers must tread carefully to ensure they don’t introduce additional risks into their software supply chain.

Brian Fox, co-founder and CTO of Sonatype, explained that AI can accelerate good engineering, but can also scale mistakes faster, especially if it doesn’t have real-world data to draw from. For example, if a model doesn’t know which versions exist or which contain vulnerabilities, the model predicts and fills in, leading to upgrades to versions that don’t exist or recommendations that break builds.

In its 2026 State of Software Supply Chain report, Sonatype analyzed more than 1.2 million malicious packages, 1,700 vulnerability records, and 37,000 AI-driven upgrade recommendations. It turned out that AI models recommended more than 10,000 non-existent versions, which equates to a hallucination rate of 27.75%.

“On a large scale, that’s not funny. It’s an operational drag: wasted developer time, broken pipelines, and people losing faith in automation. And the scarier version is when AI recommends something that exists but shouldn’t be used because it’s vulnerable, malicious, or just outside your policy. AI can help, but only if it’s limited: grounded in real registry data, fed with current vulnerability and malware intelligence, and bound by the rules your organization actually follows. Otherwise, you have plausible automation made nonsense,” said Fox.

Recent research from IDC shows that developers accept 39% of AI-generated code without revision. “Combined with Sonatype’s findings, the data suggests that AI-driven recommendations benefit from a foundation in current supply chain intelligence and enforceable policies, so that increased development speed does not increase the attack surface by default,” said Katie Norton, research manager for DevSecOps and Software Supply Chain Security at IDC.

The report also shows that overall open source adoption increased 67% year-over-year across Maven Central, PyPl, npm, and NuGet, while open source malware grew 75% over the past year.

A large portion of the traffic came from repetitive pulls such as cold caches, ephemeral CI runners, and always clean builds. Additionally, the three largest cloud service providers generated more than 108 billion requests, or 86% of downloads.

“That’s not a million developers. That’s automation on an industrial scale,” Fox said. “I’m not saying ‘take it easy.’ I say: if you operate on a machine scale, act like it. Use sustainable caching. Configure proxies and mirrors correctly. Avoid pipeline patterns that re-fetch the world every time you rebuild. This is the kind of boring technology that keeps the commons healthy, produces less carbon and keeps your buildings reliable.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Why Google Calendar Sync Is Hard (and What Tokens Have to Do With It) | HackerNoon Why Google Calendar Sync Is Hard (and What Tokens Have to Do With It) | HackerNoon
Next Article Stock Market Today: Indexes Tank As Microsoft Sparks Wider Tech Sell-Off Stock Market Today: Indexes Tank As Microsoft Sparks Wider Tech Sell-Off
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The best foldable phone you can buy
The best foldable phone you can buy
News
The Algorithmic Blind Spot: Why AI Search Can’t See Your Tech Brand | HackerNoon
The Algorithmic Blind Spot: Why AI Search Can’t See Your Tech Brand | HackerNoon
Computing
What to Watch on HBO Max in February 2026
What to Watch on HBO Max in February 2026
News
Snap launches Specs Inc ahead of smart glasses reveal this year
Snap launches Specs Inc ahead of smart glasses reveal this year
Gadget

You Might also Like

The best foldable phone you can buy
News

The best foldable phone you can buy

21 Min Read
What to Watch on HBO Max in February 2026
News

What to Watch on HBO Max in February 2026

7 Min Read
‘We need to improve Windows in ways that are meaningful for people’: Microsoft is urgently trying to fix Windows 11 issues
News

‘We need to improve Windows in ways that are meaningful for people’: Microsoft is urgently trying to fix Windows 11 issues

3 Min Read
Best power station deal: Save over ,000 on the Anker Solix F2000
News

Best power station deal: Save over $1,000 on the Anker Solix F2000

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?