• 0 Posts
  • 10 Comments
Joined 9 months ago
cake
Cake day: January 12th, 2026

help-circle





  • klankin@piefed.catoPrivacy@lemmy.ml•Deleted
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    7
    ·
    11 days ago

    How much of the codebase is AI generated? This just looks like Comaps ran through the slop machine.

    (not a personal criticism, but if you can’t write something like this, AI isn’t ever going to suddenly make you able to)



  • Oh god yeah, its just filtering through the slop that actually matters.

    But like the XZ trojan that was only affecting Debian installs, each distro needs to individually have competent maintainers to ensure their store is safe.

    If for exapmle I set a couple ‘bugfixes’ in the guix package file for emacs, I could reasonably infect a number of systems if a lazy maintainer just approved the request. (Or other attacks without even involving guix if I notied a bug in a package spelling and typo squatted it, or stole signing keys and pushed updates to the repo myself).

    None of these would change anything to other distros maintainers, but because this distros AI maintainer could risk a large number of users devices.



  • Distro package maintainers are different than software dev maintainers.

    They mean no one can be reasonably be up to date on software security updates, and (ideally) ensuring all packages changes are not malicious (as well as the small stuff like properly integrating to the distro, but idk how void works enough to comment on that)

    Cause like I can write a ton of guix configs that’ll probably run until the next ice age, but that does nothing about the dev who’s software I packaged, that now decided they’re personally god and need to spread christ as fast as possible.

    (Also off topic but that’s the power and curse of nixos-like distros, its too easy to package so odds are the shit ain’t updated, and suddenly there’s 1000 Firefox packages in nixpkgs)