Checkmarx says function-flag, malicious since July 2025 and downloaded more than 37,000 times, is still on npm with no advisory flagging it. Advisory-based scanners have nothing to match, so finding it means checking lockfiles for the campaign's eight names.
Reality
- Evidence55
- Adoption20
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
The stable AndroidX Security State libraries report patch state for the core OS, Play system modules and the Linux kernel separately, and let an app ask whether a named CVE is fixed before it turns a feature on.
Reality
- Evidence62
- Adoption30
- Hype gap+15
- Incentives
- Insufficient
- Confidence60
WorldScript Studio tracks fifteen automated reviewers in a JSON registry, and only four deterministic security scanners may block a merge. The design keeps LLM false positives off the merge path and keeps pull-request code away from the checker that judges it.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence45
Chainguard says fix generation was never its bottleneck and that responsible disclosure at scale is, so its first public batch is built from bugs upstreams quietly fixed years ago and never filed CVEs for.
Publishers:chainguard.dev
Reality
- Evidence34
- Adoption16
- Hype gap+28
- Incentives82
- Confidence48
AgentGate read the shipped code behind 30-plus OSV and GHSA flags, verified 19 npm packages as malicious, and found 18 still resolvable on publication day. Removal, not detection, is where the chain stopped.
Reality
- Evidence48
- Adoption20
- Hype gap+22
- Incentives78
- Confidence55
The engineer running Dependabot across 30 million repositories says wiring in OpenSSF's malicious-package feed was the cheap part, while normalization ate the budget and each alert ends in a build-credential incident.
Reality
- Evidence46
- Adoption62
- Hype gap−12
- Incentives64
- Confidence52
An Apify Actor read a manifest, queried OSV, and filed one triage issue, with no branch or merge rights anywhere in its schema. The run that mattered was the second one, which updated the issue instead of filing a duplicate.
Reality
- Evidence46
- Adoption12
- Hype gap+12
- Incentives74
- Confidence52
CVE-2026-45871 was made up for a test and turned out to exist. The check resolved it against a global namespace rather than against the project it was meant to defend.
Reality
- Evidence58
- Adoption10
- Hype gap−18
- Incentives40
- Confidence52
Two 2026 studies put AI-generated deployment infrastructure at worse than a coin flip, and the gates most CI pipelines run were built for application source, not config.
Reality
- Evidence58
- Adoption52
- Hype gap+12
- Incentives66
- Confidence57
METR's public discovery series shows a sharp 2026 slope change in vulnerability reports, no comparable change across seven optimization benchmarks, and slower growth in the exploited-bug catalogues.
Reality
- Evidence58
- Adoption44
- Hype gap+9
- Incentives32
- Confidence55
A single-author npm tool measured what supply-chain guards actually verify, and found documented hallucinated names alive on the registry. Provenance beats resolution.
Reality
- Evidence42
- Adoption12
- Hype gap+18
- Incentives76
- Confidence46