6 ms·
This was my first thought after they disallowed LLM contributions. They may not use AI to check for vulnerabilities but attackers are going to which puts thems
by keel-control 23d ago
This was my first thought after they disallowed LLM contributions.
They may not use AI to check for vulnerabilities but attackers are going to which puts themselves at the disadvantage.
- titularcomment 23d agoI really disagree with their acceptable usage policy, but you can't say it with certainity that LLM contributions would be a fix for this. They generate so much noise (as the primary incentive behind an independent LLM scan is often cheap contributor brownie points for your CV) that it also could lead to bogus PRs being approved or helpful PRs being lost in the noise.
- otherme123 23d agoWas this discovered by AI? Is all AI code 100% free of bugs? You are implying that just by allowing LLM contributions your product is free of bugs, and the LLM won't introduce new bugs. Of course, if the LLM introduces bugs, the solution is to add another layer of LLM looking for bugs, ad infinitum. Another post from today from Shopify, praising LLM to code their frontend, also stated that their LLM generated code is not ready to deploy, and needs to be reviewed: > It’s tempting to just point an LLM to the React Native codebase and try to one-shot the same features in native, but it doesn’t work. Even if you ask it to gather as much information as it can up front, freeze that into specs, task files, and then implement it, you end up with a huge amount of unmaintainable code that can’t be shipped. [...] each [build] must prove its behavior with tests, match the running app in a visual review, survive two adversarial code reviewers, and get a human's nod before it's committed and the next one starts.
- 1matin 23d ago> They may not use AI to *check for vulnerabilities* you didn't read the comment, did you?
- cmrdporcupine 23d ago> You are implying that just by allowing LLM contributions your product is free of bugs That... is not the implication of the comment you're replying to. You don't need to make it all fundamentalist.
- striking 23d agoDisallowing LLM contributions doesn't disqualify the use of LLMs to identify vulnerabilities.
- iCarrot 23d agoUsing LLMs for automated security audit looks like it could fall under the definition of "vibe coding" or "agent mode", which is strictly forbidden >6. It is not allowed to use AI in an autonomous-looking way to contribute in Forgejo. This also applies when someone engages in 'vibe coding' or uses so-called 'agent mode'.
- bdcravens 23d agoWhy can't you use an LLM to find vulnerabilities and then hand-code the fix? You don't even have to clean-room implement it; let the LLM write the code, and then reimplement, doing what you can to de-LLM-ify it.
- omnimus 23d agoYou can. People on Codeberg use LLMs. They are just against spam of low quality projects generated with LLMs.
- cmrdporcupine 23d agoThat is actually entirely not what they were saying at the time of the vote and its aftermath. At all. Go back and read the threads. On this forum, or on mastodon, or on the vote. It was pretty vociferously ... shall we say ... "principled" It was never stated to be about "low quality" but about use in "large part" or "majority", and when pressed people refused to define what that meant, and in fact got angry and defensive and said things like "you'll know if you've crossed the line" and "stop trying to force consent" and similar pearls of wisdom. The post-facto rationalization did in fact leave them room to judge "quality" on a purely subjective basis. I didn't stick around to find out how that would shake out.
- mitxela 23d agoDo you expect it to be enforced by a machine? Why would you need a precise definition of "majority"?
- lkjdsklf 22d agoYou don't and that's why everyone gets so angry and annoyed when people try to force precise definitions. There's no team of lawyers verifying the provenance of all code/projects submitted to codeberg. THe policy is just something they can point to as a general guidelines of what kind of shit they want to support. Everyone knows exactly what kind of projects they're talking about. The people trying to nitpick definitions are those annoying ass people at the board game night that spend half the time combing through the rule book trying to figure out why whatever they didn't like was against the rules.
- burkaman 23d agoThey did not disallow LLM contributions, and they definitely didn't disallow using LLMs to research security vulnerabilities. They only disallowed projects that are majority LLM-written. https://codeberg.org/Codeberg/org/commit/71149c7fc95ccfeae36109b5cddca339e4aa1473 https://codeberg.org/Codeberg/org/commit/71149c7fc95ccfeae36...
- badsectoracula 23d agoThat is about Codeberg, not Forgejo. Forgejo disallows LLM contributions, including using a "general AI" (they include LLMs under "general AI") for reviews[0]: > 5. Using general AI for review is forbidden. If the change contains changes to the UX it has to be approved by a human reviewer. [0] https://codeberg.org/forgejo/governance/src/branch/main/AIAgreement.md https://codeberg.org/forgejo/governance/src/branch/main/AIAg...
- burkaman 23d agoAh sorry, didn't realize they had their own policy. This is a little stronger, but you can certainly still use an LLM to search for vulnerabilities, you would just need to write fixes yourself and mention if you used an LLM for assistance. The rule you quoted is about code reviews, they don't want you using an LLM to write reviews or leave comments. This is a pretty poorly written policy to be honest, so I understand if you interpret it to mean "no LLMs in any capacity", but I think if that's what they meant they would have said that. In fact they explicitly allow content "made with the help of AI", you just have to disclose it.
- imtringued 23d agoTheir definition of vibe coding is pretty whacky. >Vibe coding is the practice where AI creates a code change (feature, bug fix, tests, refactor) with a human that describes what needs to be implemented. So if you let an AI prompt another AI without human input, that's not vibe coding? Meanwhile if you prompt the model with pseudo code you've written or code written in another programming language to translate into the target language, that's vibe coding? >It is not allowed to use AI in an autonomous-looking way to contribute in Forgejo. They used the word "in", meaning it could refer to organizational membership, their repo or theoretically any instance of Forgejo, including self hosted ones. They failed to specify what part of Forgejo or the definition of Forgejo they meant. Overall this is a pretty poorly written document and when you think about it, it doesn't really matter how poorly written it is when they are basically 100% against AI.