Post #4093524
2026-07-25 17:45 UTC
Here's an interesting one around all the "no projects with the LLM taint wanted here" discussion, taking Codeberg as example:
Codeberg offers to host binary releases
Current (FOSS) software contains hundreds or thousands of individual works as dependencies in deep dependency trees
It can be regarded as nearly certain that a substantial amount of those projects will fall under the exclusion or problematic class as per the rules above
Once complied to a release binary those "tainted" works are often included in the binary and will thus be uploaded to the forge as a release.
Hence, the forge will be hosting ToS violating material on behalf of the project subjecting the otherwise possibly compliant project to possible sanctions.
Now what do we make of that thought experiment? And how do we resolve it?
#codeberg #llm #sca #foss #compliance #fossdrama #opensource #fossdrama #drama #aiassistedcoding
Replies (2)
-
@bryan@dusty.ninja 2026-07-26 05:54
@jti42@infosec.exchange #Linux, #Windows, and #macOS all have LLM “taint” at the foundation. #Go accepts LLM patches so it seems all Go projects should be rejected. 🤷🏼♂️
-
@defnull@chaos.social 2026-07-25 17:52
@jti42@infosec.exchange Do they really 'need' to resolve this scenario? If the goal is to get rid of obvious, resource hogging, low effort projects with no real users or community, then a vague ToU rule is fine. A large gray area is fine. If a project is obviously AI and a resource hog, mods now have the option to remove it. If not, they simply do nothing. Identifying and banning all AI projects was never the goal.