← Back to context

Comment by Alien1Being

2 days ago

Debian should completely avoid AI slop.

Let the Salesforces and the Atlassians of the world destroy themselves with poor quality vibecode driven teams.

Using LLM to scan for security holes is another issue altogether.

Indeed it is, and it doesn't count as a "contribution" at all; the actual work is in fixing the CVE.

  • This is nonsense, the vast majority of critical CVEs are trivial to fix once you spot them. It's very rare that you have something like spectre where the solution is non-obvious: most of them are shit like "delete a `free`" or "put the `goto fail` in braces".

    • It’s still not an LLM contribution in a meaningful sense. The contribution is the fix, no matter how trivial it is.