• atzanteol@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    5
    ·
    11 hours ago

    The SciActive Human Contribution Policy is a free, general contribution policy meant to safeguard projects from the inherent legal and security risks of AI generated contributions.

    Boy it’s amazing how people ignore the security track record of human authored code over the last 30 years. One need only look at the recent explosion of discovered vulnerabilities by AI.

    This license is fud.

    • hperrin@lemmy.ca
      link
      fedilink
      English
      arrow-up
      3
      ·
      7 hours ago

      Nobody is ignoring anything.

      It’s not a license, it’s a policy.

      AI tends to “discover” previously discovered vulnerabilities, or obvious vulnerabilities. It also tends to hallucinate vulnerabilities. I’m not saying it’s useless at discovering vulnerabilities, just that a human audit is better.

      The policy also doesn’t say you can’t use AI to audit a code base, or even a single diff, so that point is moot.