122

Yes, he literally demands devs who don't accept LLM security reports to be removed from the project.

Projects that continue to prohibit AI-generated vulnerability reports are no longer suitable dependencies for GNOME, and should be developed someplace other than GNOME GitLab.

you are viewing a single comment's thread
view the rest of the comments
[-] RedGreenBlue@lemmy.zip 3 points 1 day ago

Scanning the code for vulnerabilities can't hurt.

[-] fodor@lemmy.zip 29 points 1 day ago

Look, if you scan code, find an exploit, write a clean patch, and submit it, nobody will give a fuck what scanning software you used.

It is the part after scanning that matters. That's what people are upset about.

[-] Thorry@feddit.org 28 points 1 day ago

Scan code, find an exploit, VERIFY THE EXPLOIT, write a clean patch and submit it.

One of the biggest issues with using LLMs for security purposes, is it makes shit up all of the time. So many false positives submitted by people who don't understand what they are doing is a huge part of why people don't accept slop security reports any more.

[-] im_fine_sandy@nord.pub 9 points 1 day ago

No one disputing that. Read the article.

this post was submitted on 04 Oct 2026
122 points (96.9% liked)

Fuck AI

8382 readers
1249 users here now

"We did it, Patrick! We made a technological breakthrough!"

A place for all those who loathe AI to discuss things, post articles, and ridicule the AI hype. Proud supporter of working people. And proud booer of SXSW 2024.

AI, in this case, refers to LLMs, GPT technology, and anything listed as "AI" meant to increase market valuations.

founded 2 years ago
MODERATORS