Applause
Applause
Posted Jul 23, 2026 16:26 UTC (Thu) by pizza (subscriber, #46)In reply to: Applause by Poliorcetics
Parent article: Codeberg: Protecting our FLOSS commons from LLMs
Last week I closed two "security issues" (which to their credit, included "fixes") that were premised on an extremely verbose "analysis" that fundamentally misconstrued the operating environment of the code in question [1]. This reduced the scope from OMGCRITICAL "security vulnerability" to mere bugs, except it also got the specifics completely wrong.
Then, after closing those issues, I re-disabled MRs entirely as the GH repo has always just been a secondary mirror.
[1] Completely offline device. One would need direct physical access [2] to exfiltrate data after a successful attack. But if one already has direct physical access... why not just exfiltrate the data directly in the first place?
[2] ie connect to it via USB or eject an SD card and plug it into a card reader
