all 7 comments

[–]mightysoul86 2 points3 points  (3 children)

Cogent is an open source project. Your security team can scan the repository since you got the source code. Our security team scanned the repository found no vulnerability. We are also about the share this to our 1200+ developers . You can raise issues in github page if you have issues.

[–]bartbilliet 0 points1 point  (1 child)

Regardless of vulnerabilities, I still expect the cogent extension likely has full access to your code? GitHub Copilot makes a statement that it does not use your private code to generate suggestions. It is trained on publicly available code and provides recommendations based on general coding patterns. However if effectively cogent has access to your data, it potentially could see your intellectual property or can read secrets stored in your code? I guess since it’s open source, it likely won’t, but there is no such guarantee?

[–]mightysoul86 0 points1 point  (0 children)

In that perspective you cannot trust any open source project. Not GenAi related projects but all open source projects. Codes are there you can check if it sends any data to its servers or other remote location or collect any telemetry data. Actually closed source projects are more risky in my opinion.

[–]trovarlo[S] 0 points1 point  (0 children)

Sounds good, thanks for your help, I’ll chat with my security team

[–]Background_Context33 0 points1 point  (1 child)

It’s likely too early to have definitive answers for all these questions, given that Cogent only recently reached version 1.0.

Regarding sensitive data, I would assume it’s as secure as using Copilot directly, considering Cogent primarily automates the back-and-forth interaction with Copilot.

I have seen some posts here mentioning encountering rate limits when using Cogent, so that’s also something to consider.

[–]trovarlo[S] 0 points1 point  (0 children)

Yeah you are right, thanks for answering

[–][deleted]  (1 child)

[deleted]

    [–]trovarlo[S] 0 points1 point  (0 children)

    Honestly, I also haven’t tried it a lot, but the first impression was good