SeCurItY IsSuE

I completely forgot about this PR until some random AI agent found a "security issue".

271 points · 11 comments · view on lemmy.world

11 Comments

Tetsuo@jlai.lu · 84 pts · 112d (1 reply)

But if the PR goes through that means it's in active development !

I think he should do a PR to change back the readme

mormegil@programming.dev · 3 pts · 109d

That's the security issue, right? Liar paradox detected!

inari@piefed.zip · 44 pts · 113d (5 replies)

What was the issue? Without looking at the PR it's hard to judge

balsoft@lemmy.ml · 43 pts · 113d

The link in the comment is borked, as expected. But the PR itself is definitely OK: https://github.com/unipop-graph/unipop/pull/138

eager_eagle@lemmy.world · 30 pts · 112d (1 reply)

it's a readme change

spizzat2@lemmy.zip · 40 pts · 112d

It was a load-bearing readme file.

JaddedFauceet@lemmy.world · 8 pts · 111d

By removing the banner, it tells the LLM that it is no longer being maintained, thus "lead to security issue".

In my company my management is using similar approach to review changes. soon more and more ppl will no longer read code and think about the code change logically, instead get scared and block changes due to these "scary AI comment"...

HeHoXa@lemmy.zip · 3 pts · 111d

Not being sure it applies to this scenario and too lazy to verify, sometimes the security scanners get updated and flag previously accepted code.

... tough to make sense of flagging a readme though, unless there's sensitive info in it.

Ephera@lemmy.ml · 28 pts · 112d (2 replies)

until some random AI agent

Wait, do they now have spam bots going around on random PRs to post advertisements?

cypherpunks@lemmy.ml · 26 pts · 112d (1 reply)

also it's from the spammer's "staging" instance, so the payload is a URL with a staging hostname which doesn't even resolve 🙄

Ephera@lemmy.ml · 26 pts · 112d

Nice, that's like the meme:

Look at how quickly AI put up a webpage for me: http://127.0.0.1/index.html