[GH-ISSUE #10880] Please update learning models to incorporate standard security guidance for CODE/Script/Configuration #69209

Closed
opened 2026-05-04 17:28:43 -05:00 by GiteaMirror · 4 comments
Owner

Originally created by @amavarick on GitHub (May 27, 2025).
Original GitHub issue: https://github.com/ollama/ollama/issues/10880

What is the issue?

Please train models to go out and get the latest STIG, CIS and OWASP guidance and incorporate it into any recommendations for code, script, server/client settings and configurations. When asking it to develop code, it will not automatically provide secure code free of SQL injection vulnerabilities etc. Please establish that if there is a conflict of settings the strictest one should be recommended. It may need to be taught how to download the latest guidance and how to extract it from XML or PDF. This is a big security issue if AI is generating unsecure code.

https://public.cyber.mil/stigs/downloads/
https://www.cisecurity.org/
https://owasp.org/www-project-top-ten/

Relevant log output


OS

No response

GPU

No response

CPU

No response

Ollama version

No response

Originally created by @amavarick on GitHub (May 27, 2025). Original GitHub issue: https://github.com/ollama/ollama/issues/10880 ### What is the issue? Please train models to go out and get the latest STIG, CIS and OWASP guidance and incorporate it into any recommendations for code, script, server/client settings and configurations. When asking it to develop code, it will not automatically provide secure code free of SQL injection vulnerabilities etc. Please establish that if there is a conflict of settings the strictest one should be recommended. It may need to be taught how to download the latest guidance and how to extract it from XML or PDF. This is a big security issue if AI is generating unsecure code. https://public.cyber.mil/stigs/downloads/ https://www.cisecurity.org/ https://owasp.org/www-project-top-ten/ ### Relevant log output ```shell ``` ### OS _No response_ ### GPU _No response_ ### CPU _No response_ ### Ollama version _No response_
GiteaMirror added the bug label 2026-05-04 17:28:43 -05:00
Author
Owner

@rick-github commented on GitHub (May 27, 2025):

This is not an ollama issue. Either log an issue with the model trainers, or the frameworks that are using models to generate code.

<!-- gh-comment-id:2913663100 --> @rick-github commented on GitHub (May 27, 2025): This is not an ollama issue. Either log an issue with the model trainers, or the frameworks that are using models to generate code.
Author
Owner

@amavarick commented on GitHub (May 27, 2025):

This was based on a request to extract STIG baselines and then make it available for future use. Note the first time it said it will extract and make available to all users yet in 2nd it said it doesn't retain past existing session. There is no logical way AI should give 2 different answers in the same session.

<!-- gh-comment-id:2913688864 --> @amavarick commented on GitHub (May 27, 2025): This was based on a request to extract STIG baselines and then make it available for future use. Note the first time it said it will extract and make available to all users yet in 2nd it said it doesn't retain past existing session. There is no logical way AI should give 2 different answers in the same session.
Author
Owner

@rick-github commented on GitHub (May 27, 2025):

The current state of this technology is not "AI". There is no intelligence. This technology is fancy auto-complete, like what your phone does when you send a message. Do not rely on "AI" for facts.

<!-- gh-comment-id:2913707524 --> @rick-github commented on GitHub (May 27, 2025): The current state of this technology is not "AI". There is no intelligence. This technology is fancy auto-complete, like what your phone does when you send a message. Do not rely on "AI" for facts.
Author
Owner

@amavarick commented on GitHub (May 27, 2025):

Thank you for the prompt response, closing request.

<!-- gh-comment-id:2913777865 --> @amavarick commented on GitHub (May 27, 2025): Thank you for the prompt response, closing request.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/ollama#69209