Yes, he literally demands devs who don’t accept LLM security reports to be removed from the project.

Projects that continue to prohibit AI-generated vulnerability reports are no longer suitable dependencies for GNOME, and should be developed someplace other than GNOME GitLab.

  • Janx@piefed.social
    link
    fedilink
    English
    arrow-up
    64
    ·
    edit-2
    5 days ago

    Gee, I can’t imagine why people are sick of having AI bullshit forced on them at every turn. Meanwhile, digital bullies literally want unpaid contributors to open-source projects kicked out if they don’t accept LLM slop…

    • iocase@lemmy.zip
      link
      fedilink
      arrow-up
      16
      ·
      5 days ago

      Its the kind of behaviour that destroys that one 3mm thick, 4m long jenga piece standing on end holding the entire planet’s tech stack stable.

  • PotatoesFall@discuss.tchncs.de
    link
    fedilink
    arrow-up
    9
    ·
    4 days ago

    They actually make a good case and have the numbers to back it up. AI has gotten quite good at spotting vulnerabilities, acknowledging that doesn’t mean being pro-AI. Ignoring it means deliberately allowing vulnerabilities. None of this entails LLM-generated code being merged into GNOME

    • ell1e@leminal.space
      link
      fedilink
      English
      arrow-up
      7
      ·
      4 days ago

      I saw this nice response below:

      Look, if you scan code, find an exploit, write a clean patch, and submit it, nobody will give a fuck what scanning software you used.

      It is the part after scanning that matters. That’s what people are upset about.

      If this dev feels like AI scans are so important, why doesn’t the dev just scan that way but then write manual bug reports? That would satisfy the no LLM bug reports rule. The problem posed in the article doesn’t seem to actually seem to exist, unless whenever people are too lazy to write a bug report on their own.

      • PotatoesFall@discuss.tchncs.de
        link
        fedilink
        arrow-up
        1
        ·
        3 days ago

        Good point. The article addresses this, their point is that the bar for sending reports in should be as low as possible and requiring re-authoring might make people not submit at all. While I agree with the author, that is still a debatable point though. I guess we would need to know how many valuable reports are actually lost by not allowing LLM-authored vulnerability reports, which is hard to do quantitatively

        • HaraldvonBlauzahn@feddit.org
          link
          fedilink
          arrow-up
          3
          ·
          2 days ago

          their point is that the bar for sending reports in should be as low as possible

          Why?

          Look: The bottleneck is not the number of reported possible issues, but the time, attention, and sustainable workload for the GNOME maintainers and developers. Anything that minimizes the latter is good.

          Also, if LLM tools really continue to improve a lot (which is doubtful IMO), a shitty, half-assed, inconplete, ill-described bug report of today that is not attended to, due to its deficit, is not lost: If the bug is real and persists, due to the proclaimed future advancements in LLM technology, maintainers will receive another much much better bug report which causes less work in a year or two. Since maintainer’s work capacity is the real bottleneck, this is a clear win!

        • expr@programming.dev
          link
          fedilink
          arrow-up
          6
          ·
          3 days ago

          That’s a fucking stupid argument. If the issue is worth addressing, the issue is worth writing up an issue.

          LLM-authored issues are the absolute fucking worst. I can’t tell you how many times I’ve had to deal with either completely fabricated issues or issues where the LLM generates bullshit “details” as though it actually investigated the issue, making it next to impossible to determine what is real or not.

          It’s not that fucking hard to just write up issues you find. We’ve been doing it for decades just fine, jfc.

  • LostWanderer@fedia.io
    link
    fedilink
    arrow-up
    46
    ·
    5 days ago

    Oofta, this man trusts unthinking things more than the collaboration of human beings. Dreadful times, it is probably Slop Simps themselves that should not be trusted due to their eagerness to take on reports that might be wrong or inaccurate.

    • fodor@lemmy.zip
      link
      fedilink
      arrow-up
      30
      ·
      5 days ago

      Look, if you scan code, find an exploit, write a clean patch, and submit it, nobody will give a fuck what scanning software you used.

      It is the part after scanning that matters. That’s what people are upset about.

      • Thorry@feddit.org
        link
        fedilink
        arrow-up
        30
        ·
        5 days ago

        Scan code, find an exploit, VERIFY THE EXPLOIT, write a clean patch and submit it.

        One of the biggest issues with using LLMs for security purposes, is it makes shit up all of the time. So many false positives submitted by people who don’t understand what they are doing is a huge part of why people don’t accept slop security reports any more.

  • HaraldvonBlauzahn@feddit.org
    link
    fedilink
    arrow-up
    5
    ·
    edit-2
    4 days ago

    I think the AI companies are trolling FOSS projects with such inflammatory proposals. Be they “anti-AI” or “pro-AI”.

    Remember before the last US election, disinformation targeted both parties to stifle more conflict. It is information warfare targeting FOSS because the tech bros and FANNG corporations do not want users with control over their software. Their relationship to FOSS is purely parasitic.

    The antidote is to center projects in actual goals and values, set really clear boundaries based on these, communicate these excellently, friendly, and firmly, and ignore the remaining people (or just bots) which keep trolling.

    If somebody wants to fork a project like GNOME and turbo-charge it with LLMs, let them prove they can do better and find users who want the slop.

  • Denjin@feddit.uk
    link
    fedilink
    arrow-up
    6
    ·
    5 days ago

    Not only is Gnome a terrible desktop environment, turns out it’s also developed by a terrible person.

  • im_fine_sandy@nord.pub
    link
    fedilink
    English
    arrow-up
    4
    ·
    4 days ago

    The solution is to make the policy about quality rather than AI use, and just bounce all the bug reports that are AI slop.

  • moldy_rice@piefed.keyboardvagabond.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 days ago

    That’s actually the best use of AI.

    Ban AI contributions because of the copyright risk. But there’s no risk in getting code analysis from AI.

    Worst case it’s just noise. Best case, it’ll find unauthenticated RCEs.

    • Sonnenblume@discuss.tchncs.deOPM
      link
      fedilink
      arrow-up
      10
      ·
      4 days ago

      If you want to interact with the autoconfabulator that is your decision, I would prefer you didn’t and I would very much like you not feeding my work into one of those things but whatever. If you can come up with a valid report that way and write a proper bug report, I can work with that. What I take massive issue with is mandating everybody to use LLMs and calling for their removal from the project if they do not want to do that.