← Back to context

Comment by bdcravens

21 hours ago

Why can't you use an LLM to find vulnerabilities and then hand-code the fix? You don't even have to clean-room implement it; let the LLM write the code, and then reimplement, doing what you can to de-LLM-ify it.

You can. People on Codeberg use LLMs. They are just against spam of low quality projects generated with LLMs.

  • That is actually entirely not what they were saying at the time of the vote and its aftermath. At all.

    Go back and read the threads. On this forum, or on mastodon, or on the vote. It was pretty vociferously ... shall we say ... "principled"

    It was never stated to be about "low quality" but about use in "large part" or "majority", and when pressed people refused to define what that meant, and in fact got angry and defensive and said things like "you'll know if you've crossed the line" and "stop trying to force consent" and similar pearls of wisdom.

    The post-facto rationalization did in fact leave them room to judge "quality" on a purely subjective basis. I didn't stick around to find out how that would shake out.

    • I assume you are implying that LLM generated projects don't mean bad quality. That's true. At same time we all know what this means. Plausibly looking projects that might even work but have little human oversight. There are so many of them It's really difficult to know. I don't want to depend on such code and I bet neither do most programmers. Why? Because by then you might as well vibe the library yourself and be the one who does the oversight.

      I might be wrong but I doubt that people on Codeberg are against use of LLMs that make the projects better. Like finding security leaks. What these rules are aimed at are hosting of endless vibe coded projects that are just copy of each other.

You can, though some people are going to be annoyed by it and just publish a zero day out of spite.