| ▲ | computably 5 hours ago | |||||||||||||
Spending their time patching, or reviewing slop "patches"? | ||||||||||||||
| ▲ | usef- 5 hours ago | parent [-] | |||||||||||||
They're not slop, if you're talking about recent ones. You might still be operating on information for a year or two ago. Here's the curl project talking about the strain they're under from real reports (despite being a mature and well-vetted project): > A thirty years old project could make you think you’ve seen most things already, but we have not been in this situation before. > The rate of incoming security reports is 4-5 times higher than it was in 2024 and double the speed of 2025 – meaning that on average we now get more than one report per day. The quality is way higher than ever before. The reports are typically very detailed and long. - https://daniel.haxx.se/blog/2026/05/26/the-pressure/ --- Linux kernel maintainer Greg Kroah-Hartman: > "Something happened a month ago, and the world switched. Now we have real reports." It's not just Linux, he continued. "All open source projects have real reports that are made with AI, but they're good, and they're real." Security teams across major open source projects talk informally and frequently, he noted, and everyone is seeing the same shift. "All open source security teams are hitting this right now." - https://www.theregister.com/software/2026/03/26/linux-kernel... --- And ffmpeg, who previously complained about slop, 2025: https://xcancel.com/FFmpeg/status/1984220199193891166 Now say serious issues are being found, 2026: https://xcancel.com/FFmpeg/status/2066169070387413147 (I only point out their previous stance to show that they're not coming from pure AI hype.) | ||||||||||||||
| ||||||||||||||