← Back to context

Comment by trollbridge

2 days ago

Indeed it is, and it doesn't count as a "contribution" at all; the actual work is in fixing the CVE.

This is nonsense, the vast majority of critical CVEs are trivial to fix once you spot them. It's very rare that you have something like spectre where the solution is non-obvious: most of them are shit like "delete a `free`" or "put the `goto fail` in braces".

  • It’s still not an LLM contribution in a meaningful sense. The contribution is the fix, no matter how trivial it is.