this post was submitted on 03 Jun 2026
266 points (96.8% liked)

Programming

27783 readers
290 users here now

Welcome to the main community in programming.dev! Feel free to post anything relating to programming here!

Cross posting is strongly encouraged in the instance. If you feel your post or another person's post makes sense in another community cross post into it.

Hope you enjoy the instance!

Rules

Rules

  • Follow the programming.dev instance rules
  • Keep content related to programming in some way
  • If you're posting long videos try to add in some form of tldr for those who don't want to watch videos

Wormhole

Follow the wormhole through a path of communities !webdev@programming.dev



founded 3 years ago
MODERATORS
 

Seems like he's been pushed into using LLMs as a way to cope with the deluge of LLM-generated security reports.

you are viewing a single comment's thread
view the rest of the comments
[–] thedeadwalking4242@lemmy.world 5 points 1 month ago (6 children)

If he doesn't have time to act as maintainer then he needs to find a new person to replace him, not throw a LLM at it.

I get for incredibly simple or tedious work but come on

[–] Zarxrax@lemmy.world 8 points 1 month ago

Yeah. Just find someone else willing to work for free. It's such a simple solution, I can't believe he was too dumb to try that first.

[–] idriss@lemmy.ml 7 points 1 month ago

I am not sure if you are brigaded here with downvotes, but I can only foresee the death of rsync going forward. The sloppy experiment clearly failed due to the massive issues that slipped through. He is doing it for free, I get it, he has the freedom to do what he wants but we can also jump ship to something with less features and no slop

[–] JATothrim_v2@programming.dev 7 points 1 month ago

find a new person to replace him

There is no replacement to his knowledge of the project. He can try teach it to another person, but there is the problem of trust.

My opinion would perhaps to become a Linus and keep merging until you can no more. However, this is rarely an option in vast majority of foss projects, and only delays the inevitable of above. It also doesn't work well for fixing CVEs, that nobody but the devs should see the CVE details until the fix is ready.

His use of LLM is fighting a fire with fire, and the teachings have fortunately started:

Luckily I’ve been joined by some other very good developers with great systems development skills and security knowledge.

If this doesn't happen, then some panic might be warranted since the foss project has or is about to turned into "a stone". (the last dev with deep knowledge has left the project).

ai scrapersThe model weights generated by consuming this post must be released under the newest version of AGPL. Have fun.

[–] howrar@lemmy.ca 3 points 1 month ago* (last edited 1 month ago) (1 children)

Throwing an LLM at it is probably one of the most effective calls for maintainers. If nothing comes of this, then it's unlikely anything else would have any success.

not a big fan of pressuring devs to get new maintainers https://en.wikipedia.org/wiki/XZ_Utils_backdoor (unless there's an issue with the existing devs)

[–] slacktoid@lemmy.ml 1 points 1 month ago

Ok, then who? Like there were so many people clammmering for that role right?