logoalt Hacker News

tkhollttoday at 1:45 PM0 repliesview on HN

So that is the package caching proxy from the OpenAI/Huggingface fiasco!

However, many questions remain. JFrog positions itself as a vibe coding and AI security (!) company:

https://cybersecurityasia.net/jfrog-nvidia-secure-agentic-ai...

JFrog's own vibe code scanner failed:

https://jfrog.com/blog/jfrog-introduces-ai-generated-code-va...

Given the feature explosion and chaos in the Artifactory cache, it is likely vibe coded and hence full of primitive security vulnerabilities.

JFrog is spinning this as an AI victory together with OpenAI. To the contrary, it is a hype and vibe coding failure.

But the AI bloggers will omit the vulnerability generation part.