113

Yes, he literally demands devs who don't accept LLM security reports to be removed from the project.

Projects that continue to prohibit AI-generated vulnerability reports are no longer suitable dependencies for GNOME, and should be developed someplace other than GNOME GitLab.

all 22 comments
sorted by: hot top new old
[-] PotatoesFall@discuss.tchncs.de 2 points 1 hour ago

They actually make a good case and have the numbers to back it up. AI has gotten quite good at spotting vulnerabilities, acknowledging that doesn't mean being pro-AI. Ignoring it means deliberately allowing vulnerabilities. None of this entails LLM-generated code being merged into GNOME

[-] ell1e@leminal.space 3 points 59 minutes ago* (last edited 58 minutes ago)

I saw this nice response below:

Look, if you scan code, find an exploit, write a clean patch, and submit it, nobody will give a fuck what scanning software you used.

It is the part after scanning that matters. That’s what people are upset about.

If this dev feels like AI scans are so important, why doesn't the dev just scan that way but then write manual bug reports? That would satisfy the no LLM bug reports rule. The problem posed in the article doesn't seem to actually seem to exist, unless whenever people are too lazy to write a bug report on their own.

[-] Janx@piefed.social 55 points 1 day ago* (last edited 1 day ago)

Gee, I can't imagine why people are sick of having AI bullshit forced on them at every turn. Meanwhile, digital bullies literally want unpaid contributors to open-source projects kicked out if they don't accept LLM slop...

[-] iocase@lemmy.zip 14 points 1 day ago

Its the kind of behaviour that destroys that one 3mm thick, 4m long jenga piece standing on end holding the entire planet's tech stack stable.

[-] heavy@sh.itjust.works 5 points 19 hours ago

More slop for the slop god.

[-] HaraldvonBlauzahn@feddit.org 2 points 17 hours ago* (last edited 17 hours ago)

I think the AI companies are trolling FOSS projects with such inflammatory proposals. Be they "anti-AI" or "pro-AI".

Remember before the last US election, disinformation targeted both parties to stifle more conflict. It is information warfare targeting FOSS because the tech bros and FANNG corporations do not want users with control over their software. Their relationship to FOSS is purely parasitic.

The antidote is to center projects in actual goals and values, set really clear boundaries based on these, communicate these excellently, friendly, and firmly, and ignore the remaining people (or just bots) which keep trolling.

If somebody wants to fork a project like GNOME and turbo-charge it with LLMs, let them prove they can do better and find users who want the slop.

[-] raspberriesareyummy@lemmy.world 23 points 1 day ago

What a piece of shit. Sadly one among many :(

[-] LostWanderer@fedia.io 46 points 1 day ago

Oofta, this man trusts unthinking things more than the collaboration of human beings. Dreadful times, it is probably Slop Simps themselves that should not be trusted due to their eagerness to take on reports that might be wrong or inaccurate.

[-] fodor@lemmy.zip 10 points 1 day ago

Fuck that guy.

[-] AceFuzzLord@lemmy.zip 7 points 1 day ago

Karma would be every single project ditching that toxic dump site.

[-] RedGreenBlue@lemmy.zip 4 points 1 day ago

Scanning the code for vulnerabilities can't hurt.

[-] fodor@lemmy.zip 28 points 1 day ago

Look, if you scan code, find an exploit, write a clean patch, and submit it, nobody will give a fuck what scanning software you used.

It is the part after scanning that matters. That's what people are upset about.

[-] Thorry@feddit.org 26 points 1 day ago

Scan code, find an exploit, VERIFY THE EXPLOIT, write a clean patch and submit it.

One of the biggest issues with using LLMs for security purposes, is it makes shit up all of the time. So many false positives submitted by people who don't understand what they are doing is a huge part of why people don't accept slop security reports any more.

[-] im_fine_sandy@nord.pub 9 points 1 day ago

No one disputing that. Read the article.

[-] im_fine_sandy@nord.pub 1 points 1 day ago

The solution is to make the policy about quality rather than AI use, and just bounce all the bug reports that are AI slop.

this post was submitted on 04 Oct 2026
113 points (96.7% liked)

Fuck AI

8382 readers
1691 users here now

"We did it, Patrick! We made a technological breakthrough!"

A place for all those who loathe AI to discuss things, post articles, and ridicule the AI hype. Proud supporter of working people. And proud booer of SXSW 2024.

AI, in this case, refers to LLMs, GPT technology, and anything listed as "AI" meant to increase market valuations.

founded 2 years ago
MODERATORS