Flathub moves to ban nearly all apps and submissions made with generative AI

https://www.gamingonlinux.com/2026/05/flathub-moves-to-ban-nearly-all-apps-and-submissions-made-with-generative-ai/

107 points · 10 comments · view on lemmy.world

10 Comments

hperrin@lemmy.ca · 9 pts · 89d

That’s some good news.

minfapper@piefed.social · -22 pts · 90d (8 replies)

Maybe if they took security even remotely seriously and made a functioning sandbox (that apps can't trivially opt themselves out of), we wouldn't have to care whether an app was AI generated or not.

Yes, containers/sandboxes have vulnerabilities that really clever attackers can exploit, but AI generated slop can't.

usernamesAreTricky@lemmy.ml · 10 pts · 90d

Speaking broadly: Plenty of other issues or security vulnerabilities can exist that a good sandbox won't catch. Like software can insecurely store and transmit passwords, have bad randomness for something security sensitive, secretly be mining crypto behind the scenes and burn through battery/electricity, etc.

SupraMario@lemmy.world · 4 pts · 89d (5 replies)

Yes, containers/sandboxes have vulnerabilities that really clever attackers can exploit, but AI generated slop can't.

Wait are you suggesting that AI slop code can't have vulnerabilities? Cause... that's hilariously not even remotely true. It's a huge issue in SecOps, it was even an issue in the past when humans didn't have a "easy" button and every vibe coder dumped commits. It's way worse now because a lot of the vibe coded shit isn't checked, and the people who produce it have no clue what the fuck it does in the first place.

lelgenio@lemmy.ml · 5 pts · 89d (4 replies)

Wait are you suggesting that AI slop code can't have vulnerabilities?

I think they mean "containers can have security vulnerabilities, but you need to be cleaver to exploit them, AI slop is not clever enough to exploit those vulnerabilities"

corsicanguppy@lemmy.ca · 2 pts · 89d (1 reply)

cleaver

lelgenio@lemmy.ml · 1 pts · 89d

kurcatovium@piefed.social · 1 pts · 89d (1 reply)

But AI slop probably introduces plenty of new vulnerabilities, right?

lelgenio@lemmy.ml · 3 pts · 89d

Yes? Banning it form Flathub is a good thing

corsicanguppy@lemmy.ca · 2 pts · 89d

took security even remotely seriously

There's a reason they're at SLSA1 . And this is it.

Plot twist: SLSA4 has been achievable since like 1998. Sit DOWN, Debian.