Using generative artificial intelligence with asset tagging for code security
A build artifact to be used in an application in a development pipeline and information associated with the build artifact is identified. Metadata including the information associated with the build artifact is generated. The metadata is associated with the build artifact, wherein the metadata conveys with the build artifact in the development pipeline.
1 . A method comprising:
identifying a build artifact and information associated with the build artifact, the build artifact to be used in an application in a development pipeline;
generating, by a processing device, metadata comprising the information associated with the build artifact; and
associating the metadata with the build artifact, wherein the metadata conveys with the build artifact in the development pipeline;
wherein identifying the build artifact and information associated with the build artifact includes:
receiving a request to analyze the build artifact to identify security vulnerabilities in the build artifact, and
analyzing the build artifact to determine whether the build artifact includes the security vulnerabilities, wherein analyzing the build artifact includes the processing device executing a generative artificial intelligence (AI) model that analyzes the build artifact.
2 . The method of claim 1 , wherein the development pipeline is a continuous integration and continuous delivery (CI/CD) pipeline.
3 . The method of claim 1 , wherein the information associated with the build artifact comprises one or more of a source of the build artifact, a commit identifier, or a user associated with the commit identifier.
4 . The method of claim 1 , wherein the information associated with the build artifact comprises a software bill of materials (SBOM) for the build artifact.
5 . The method of claim 1 , wherein generating the metadata comprising the information associated with the build artifact further comprises encrypting the metadata.
6 . The method of claim 1 , wherein identifying the build artifact for the application in the development pipeline further comprises:
in response to determining that the build artifact lacks the security vulnerabilities, generating the metadata that includes an indication that the build artifact lacks the security vulnerabilities.
7 . The method of claim 1 , wherein identifying the build artifact for the application in the development pipeline further comprises:
in response to determining that the build artifact has one or more security vulnerabilities, generating the metadata that includes an indication that the build artifact has the one or more security vulnerabilities.
8 . The method of claim 7 , further comprising:
providing, by the generative AI model, one or more recommended solutions to the one or more security vulnerabilities.
9 . The method of claim 7 , further comprising:
generating content describing context associated with the determination that the build artifact has the one or more security vulnerabilities; and
providing the content to a sender of the request to analyze the build artifact.
10 . The method of claim 1 , wherein the information associated with the build artifact comprises one or more capabilities associated with the build artifact.
11 . The method of claim 10 , wherein the processing device executing the generative AI model further comprises:
reading the metadata comprising the information associated with the build artifact, the metadata comprising the one or more capabilities associated with the build artifact;
identifying current capabilities of the build artifact;
determining that the current capabilities differ from the one or more capabilities indicated in the metadata; and
generating an indication that the current capabilities differ from the one or more capabilities indicated in the metadata.
12 . A non-transitory computer readable storage medium storing instructions which, when executed, cause a processing device to:
identify a build artifact and information associated with the build artifact, the build artifact to be used in an application in a development pipeline;
generate metadata comprising the information associated with the build artifact; and
associate the metadata with the build artifact, wherein the metadata conveys with the build artifact in the development pipeline;
wherein to identify the build artifact and information associated with the build artifact, the processing device is further to:
receive a request to analyze the build artifact to identify security vulnerabilities in the build artifact, and
analyze the build artifact to determine whether the build artifact includes the security vulnerabilities, wherein analyzing the build artifact includes the processing device to execute a generative artificial intelligence (AI) model that analyzes the build artifact.
13 . The non-transitory computer readable storage medium of claim 12 , wherein to identify the build artifact for the application in the development pipeline, the processing device is further to:
in response to determining that the build artifact has one or more security vulnerabilities, generate the metadata that includes an indication that the build artifact has the one or more security vulnerabilities.
14 . The non-transitory computer readable storage medium of claim 13 , wherein the processing device executing the generative AI model is further to:
provide one or more recommended solutions to the one or more security vulnerabilities.
15 . The non-transitory computer readable storage medium of claim 13 , wherein the processing device executing the generative AI model is further to:
generate content describing context associated with the determination that the build artifact has the one or more security vulnerabilities; and
provide the content to a sender of the request to analyze the build artifact.
16 . The non-transitory computer readable storage medium of claim 13 , wherein the processing device executing the generative AI model is further configured to generate a polygraph.
17 . The non-transitory computer readable storage medium of claim 12 , wherein the information associated with the build artifact comprises one or more capabilities associated with the build artifact.
18 . The non-transitory computer readable storage medium of claim 17 , wherein the processing device executing the generative AI model is further to:
read the metadata comprising the information associated with the build artifact, the metadata comprising the one or more capabilities associated with the build artifact;
identify current capabilities of the build artifact;
determine that the current capabilities differ from the one or more capabilities indicated in the metadata; and
generate an indication that the current capabilities differ from the one or more capabilities indicated in the metadata.
19 . The non-transitory computer readable storage medium of claim 12 , wherein to identify the build artifact for the application in the development pipeline, the processing device is further to:
in response to determining that the build artifact lacks the security vulnerabilities, generate the metadata that includes an indication that the build artifact lacks the security vulnerabilities.