| ▲ | Gigachad 7 hours ago | ||||||||||||||||
The open for anyone PR model might be at risk now. How can maintainers be expected to review unlimited slop coming in. I can see a lot of open source just giving up on allowing community contribution. Or maybe only allowing trusted members to contribute after they have demonstrated more than passing interest in the project. | |||||||||||||||||
| ▲ | pixl97 5 hours ago | parent [-] | ||||||||||||||||
It has been at risk for a long time, now it is in doubt. Think of a scenario like Attacker floods you with tons of AI slop to make your overloaded and at risk of making mistakes. These entries should have just enough basis in reality to avoid summary rejection. Then the attacker puts in useful batch of code that fixes issues and injects a tricky security flaw. If there's not a lot going on the second part is hard to pull off. But if you ruin the SnR it becomes more likely. | |||||||||||||||||
| |||||||||||||||||