No LLM Code in Dependencies
joeyh.name
joeyh.name
It looks like git after 2.22 was dropped because it took an LLM commit. Same with ghc.
If I have to choose between this or git and the latest ghc, I think I'm going to just wait for someone to fork annex.
I don't even feel strongly one way or the other on AI stuff; pragmatically, I'm just not going to stop using the most widely used version controller, or Haskell, just for some guy's (forkable, AGPL licensed) hobby project.
Looks like they are aware, and git-annex has been around for decades written by one of the best Haskellers. “Some guys hobby project” is not fair
They said git-annex supports git back to 2.22. Not git after 2.22 was dropped.
An incompatible change in ghc would break compilation of other software also.
And those we've let into our codebases with no concerns. Hell, some even threw parties inviting in more of them.
At least LLMs don't call HR on you when you rightfully tell them that they're full of shit. Though.. well. Claude probably might.
If there is a bug, its because you are a lazy piece of shit, not because humans make mistakes, and you missed it. It is branded slop.
We're living in interesting times, socially, OSS will die because of this.
Contributors are dwindling, and will continue to do so. If you want to play in your sandbox, please do. Don't open-source, keep it to yourself.
The sloppers are diving head-first into a world where not knowing how a basic idea translates to code is embraced. This is not true of every slopper, but it is true of enough that sloppers are a threat.
The problem is you've redefined LLM-coding as slopping. "This is not true of every slopper".
I'd venture to say that a large number of developers are using LLM tooling at this point. Not all of those developers are out there generating massive, poorly engineered PRs and wasting project maintainer time. For me there are at least those 3 broad categories of user of LLMs for software development, maybe more if I sat and thought about it for a while.
Note that a ban on LLM-generated code is not a prohibition on other forms of LLM-based assistance. Those other forms don't incur a direct burden on the maintainers.
OSS will not die.
I am wondering though if that was really the world we were living in just before chatGPT launched, given that the whole OSS thing was already harvested super hard.
The "mentoring opportunities" often were just extracting free consulting out of experts + building a portfolio for getting hired by big tech.
Would we really want to go back to that?
So I agree with the idea but only in a vacuum, I think.
I disagree. Behind an LLM sits a developer. They steer the LLM. For them, directions to the LLM is the preferred form of modification of the software. The output of the LLM is not a preferred form anymore. This poses a huge problem for free software, especially when the LLM that translates preferred form into "source code" is not FOSS.
The low-tier dev was not used in this way.
Or rather I envy you for your experience with humans so far.
These days, my only deps are TinyUSB and LVGL - stuff that would be completely pointless and absurd to recreate.
How do you get your code to the point where it has no dependencies? How do you do any sort of database writing without a library, or web access without sockets from an os library?
What sort of code has no dependencies? I'm now very curious as I can't see how you can do anything without altest including the std lib from your OS to do any file i/o.
But other than that, totally dependency free!
With SO there's an unclear problem and a closed as duplicate being served if we're being real.
(FYI I'm not disputing that the LLM vendors didn't steal, that doesn't mean the technology is shit)
LLM detection in writing is basically today's polygraph test pseudoscience. There was a blog a while ago where someone fed classic literature into one and it was detected as probably AI.
Agents as a super powered (re)search assistant is underrated.
I would be surprised if there is no LLM-assisted code in there prior to this commit, this is just the first where the author chose to disclose it.
If you aren’t happy with their stance towards LLMs you can fork and fix yourself if you feel it’s necessary.
(Update: you're a Debian developer so you're even more familiar with how that world works than I am.)
I'm merely trying to establish that it's bad. A lot of HN seems to be cheering for the badness. That is, to me, unfathomable.
I've pointed out to you that LLMs are forced onto people. I fear you are out of touch with the job market requirements of 2026.
All I'm trying to say here is that slopcode is generally a bad idea. If you are forced to slopcode to earn a living, I am not saying you shouldn't do that ("be a purist", as you'd put it). I'm just trying to point out that HN doesn't seem to generally acknowledge that concept as being bad.
Slop is not okay, this isn't disputed.
When you say "If you are forced to slopcode" you are implying that LLMs (or humans who operate the tools) can only produce slop with it.
No.
Just because you are forced to use an LLM, does not mean you can only produce slop.
I can imagine LLMs becoming a mainstay, but what you are describing isn't wholly different from sufficiently advanced static code analysis - where you'd want more determinism than most LLMs normally provide.
The problem is that such a thing might take a decade and billions of dollars of investments to create per-language (e.g. actually useful code analysis for Java, for Spring Boot, for processing and validating form data, and DB schemas and document processing and rendering reports etc., literal domain checks for anything and everything that is common across various enterprises) so nobody wants to do that, so it's easier to throw LLMs at it and call it good enough.
Most bugs are far too nuanced to be caught by static analysis imo, you do need to actually understand what's going on in the program, the intent, the environment, etc. instead of blindly verifying if everything technically checks out, compilers already do a perfect job at that.
So who's responsible for all of the Spring Dependency Injection bullshit with circular dependencies and AOP issues, stuff like @Transactional only working when called from a different bean, as well as the other hundreds of issues I've seen throughout the years? One can't just ignore that, because in many places that is most of the job market (alongside maybe .NET or PHP).
There's got to be some traditional way to spot every single one of the states that can be represented in code by the frameworks available in a given language, surely the correct answer is not "Yeah, an LLM said it looks okay because it's close enough to some training data that we have." It might be the practical answer, but only because all of our tech is built wrong.
Then again, writing provably correct code might be impossible in Java, at least with the currently available tools, because the ecosystem is such that the compiler can't do anything about all of the dynamic stuff that evil developers make you deal with at runtime.
Man do I enjoy my totally real full self driving.
For me, for all intents and purposes, self driving is here today.
> In ten years we'll be drowning in subtle bugs introduced by the unreliable garbage that is machine-generated code
Yes. But replace
> and the industry will hopefully have learned to never rely on anything that wasn't at least seriously looked over by an actual thinking human being that understands it.
with: "and the industry will throw even more LLMs at the problem, producing an even deeper soup of garbage that in some cases perform a tiny bit better, and when things do break it's always the fault of someone else. So for example a bank denies you a mortgage or an insurance company fails to process your claim, and you are almost certain that it's due to some slopcode somewhere, but you have to suck it up because the world has become accustomed that this is just how things are done."
It's a way of breaking computers that I'd never thought I'd see. We're wilfully taking the one cool thing about computers – them exactly interpreting instructions carefully crafted by humans to do exactly the right thing – with bucketloads of vibes that hopefully mostly do the right thing most of the time ("the tests pass"). What the hell are we doing.
When $llm_company begins asking you to open your wallet to fix every vulnerability, bug, or other breaking issue, instead of the guy in Nebraska doing it for free because someone mentored him, will the economics change? Probably not.
Everyone and their cat can look at open source projects, which can and will result in being called out publicly. This can also have legal ramifications on the project itself.
Spotify is running ads for a design "thing", that's basically a generative AI logo creator. Isn't that one of the few instances that's already been clearly put into law - that you can't copyright AI generated stuff? How can you create a business that's selling uncopyrightable logos (which definitely would need/want to be copyrighted/trademarked)? It's the Wild, Wild West out here.
But maybe we are thinking about it backward. Have you ever wondered why there is so much "free software"? Beware of strangers bearing gifts.
I have always wondered and been suspicious of people who are so eager for you to use their software. Which isnt to say OSS isnt high quality. Im just saying that maybe when people are pushing free software on you they are kind of in it for themselves.
As for whats next, me personally, last year I pulled all my personal repos about 80 of them off of bitbucket and self host that all now. I think OSS projects should setup a paywall and charge money to create PRs.
Like 10-100 bucks per PR to cover the cost of the extra vigilance. Also I could see migrations away from github, to AI free dependency hosting or something like that. Its an interesting challenge. But its not insurmountable.
Either paywall OSS projects or take them off the interwebs. Also one option the OP didnt explore I dont think is forking and freezing the dependencies. Huge maintenance burden, but its better than source corruption.
Also use fewer dependencies. Maybe set a limit of 5.
I strongly disagree with this. The free (as in both freedom and as in free beer) software movement was to provide an alternative to proprietary and closed-source software, which is developed by people and corporations who are openly in it for themselves.
> Like 10-100 bucks per PR to cover the cost of the extra vigilance. Also I could see migrations away from github, to AI free dependency hosting or something like that. Its an interesting challenge. But its not insurmountable.
You could just leave your project where it's at, keep it open source, and simply not accept outside contributions. Lots of open source software operates this way. The Ladybird browser notably switched to this model recently as a reaction to AI pull requests.
looks like a normal html-only website to me