← Back to context

Comment by cmeacham98

5 days ago

A "focused identity" with no links to other identities is anonymous by definition.

More importantly, this project is not "zero trust" and calling it such is borderline deceptive.

I can verify the artifacts you're shipping contain the code in the repo (or I could just clone the repo myself), but I cannot automatically verify that your code is non-malicious and free of bugs. That is what I am trusting when using your software, and I have serious doubts about the "free of bugs" part for AI generated software.

I’m right there with you in mistrusting AI generated code but - you also can’t automatically verify that human-written code is non-malicious and bug free.