We Have a Package for You! A Comprehensive Analysis of Package Hallucinations by Code Generating LLMs

LLMs hallucinating package names is a severe threat to software supply chains. Up to 21% of generated code recommends non-existent packages. Are we really ready to let LLMs write our code when they can’t even get dependencies right?

Posted on 01 Oct 2024