Hacker News new | ask | show | jobs
by 20k 26 days ago
Analysing codebases with LLMs to find security vulnerabilities is completely unrelated to committing code generated with LLMs
2 comments

It's a fair comparison. There's a fair amount of plausible-sounding bullshit being peddled as a transparent advertisement for an ai-driven "code security" firm.
and how do you propose fixing the hundreds, if not thousands, of valid, impactful security bugs that frontier models will find?
That seems like an unfounded assumption. Why should one assume that Git Annex has hundreds or thousands of critical, exploitable security vulnerabilities?
This isn't a problem that is isolated to Git Annex. There are many maintainers out there taking anti-LLM stances, and you don't have to look very far to find OSS projects drowning from the wave of bugs.

https://daniel.haxx.se/blog/2026/05/26/the-pressure/

Wave of bug reports which is quite a different thing.

If you aren’t happy with their stance towards LLMs you can fork and fix yourself if you feel it’s necessary.

If you can't fix them without LLMs, then you can't fix them. You probably shouldn't be trusted with maintaining the codebase in the first place.
How about if you don't have time to fix them without LLMs?
Then you don't have time to maintain the codebase. Sad, but sometimes true.
When given the choice between putting food on the table, and being a purist, I'd take some bread. It is hard out there.
Sure. I did not mean to throw shade at people whose professional survival depends on doing this.

I'm merely trying to establish that it's bad. A lot of HN seems to be cheering for the badness. That is, to me, unfathomable.

Welcome to volunteer-driven open source.

(Update: you're a Debian developer so you're even more familiar with how that world works than I am.)