Live data from Hacker News

No LLM Code in Dependencies

joeyh.name

91–100 of 120 posts

Re: No LLM Code in Dependencies

#91
post #58
post #50

What confuses me about this stance is that LLMs are basically indistinguishable from any mid-to-low-tier dev. And those we've let into our codebases with no concerns. Hell, some even threw parties inviting in more of them. At least LLMs don't call HR on you when you rightfully tell them that they're full of shit. Though.. well. Claude probably might.

Godot's recent announcement spelled something out clearly: when a mid-tier rando contributes, you can provide feedback to that person and possibly help them grow into being a senior contributor or even a maintainer. That possibility of helping the human behind the code is part of the motivation for doing open-source. Mentoring shitty devs is itself giving back to the community, in a different form than the code itsel…

I think I'm also going to refer people to the Godot foundation's statement on this from now on. Too often people try to lay it out like a moral conundrum, or some kind of purity test for "real" programmers vs larpers, but that's all just lips flapping. Meanwhile there are real-life practical consequences that follow taking AI contributions, and the Godot foundation has done a great job articulating what those things are. It's very nice for there to be a voice like saying these things.

Re: No LLM Code in Dependencies

#92
post #63

Earlier quoted context omitted.

I think you're wrong. And I think that FOSS is our last best hope to keep software under the control of the individual. The sloppers are diving head-first into a world where not knowing how a basic idea translates to code is embraced. This is not true of every slopper, but it is true of enough that sloppers are a threat.

I hear you, but again there are a lot of assumptions in this statement: "sloppers are diving head-first into a world where not knowing". The problem is you've redefined LLM-coding as slopping. "This is not true of every slopper".

I find your comment here interesting. The parent never called out LLM-coding, they said "sloppers". If we take that choice of word as deliberate, it stands to reason there's a distinction there between "sloppers" and LLM assisted coding in general. You quoting "This is not true of every slopper" as proof they are equating the two seems like a weakly defended assertion. It's entirely possible there are 3 broad classes of LLM users in the parent's explicit and implicit beliefs. The thing is, you don't know any more than I know. You are attributing a held belief to someone that you inferred from incomplete information. That being said, if you based your assertion on external, unreferenced knowledge, then you could potentially know they hold that belief.

I'd venture to say that a large number of developers are using LLM tooling at this point. Not all of those developers are out there generating massive, poorly engineered PRs and wasting project maintainer time. For me there are at least those 3 broad categories of user of LLMs for software development, maybe more if I sat and thought about it for a while.

Re: No LLM Code in Dependencies

#93

Earlier quoted context omitted.

I hear you, but again there are a lot of assumptions in this statement: "sloppers are diving head-first into a world where not knowing". The problem is you've redefined LLM-coding as slopping. "This is not true of every slopper".

I find your comment here interesting. The parent never called out LLM-coding, they said "sloppers". If we take that choice of word as deliberate, it stands to reason there's a distinction there between "sloppers" and LLM assisted coding in general. You quoting "This is not true of every slopper" as proof they are equating the two seems like a weakly defended assertion. It's entirely possible there are 3 broad classes…

The article is about LLM code. I’m sure you can condense the many lines into less than 5 lines. I’m not sure what you are trying to say.

Re: No LLM Code in Dependencies

#94
These arguments are increasingly smelling strawman-ish to me. The authors seem to pick the absolute worst possible examples of LLM usage in software development, ignoring the fact that it is ultimately just a tool, and that all the blame for a shitty product continues to lie at the feet of the one wielding it like a giant doofus.

Re: No LLM Code in Dependencies

#95

Earlier quoted context omitted.

LLMs are worse at programming than any dev I've ever worked with. Yes, even $latest_model. They have no understanding or ability to reason, and they make mistakes no human would make. They are, in short, bad at programming.

You've not worked with average developers then, or this is a purely reactionary/emotional statement.

In my experience it's always been easier to work with terrible human programmers because the terribleness of their code is inherently bound to human comprehension. Of course I've seen some absolutely massive messes created by humans. But generally if a human wrote it then a human can understand it. Also it takes an amount of time and effort for a human to create this kind of mess which tends to actually be more effort than what a more experienced person will expend to fix what is wrong with it. LLMs flip all this on it's head. Plus there's the thing the Godot statement talks about. I have a completely different willingness to help a struggling noob rise through the same trajectory I did, compared to fixing someone else's LLM code.

Re: No LLM Code in Dependencies

#96
post #50

What confuses me about this stance is that LLMs are basically indistinguishable from any mid-to-low-tier dev. And those we've let into our codebases with no concerns. Hell, some even threw parties inviting in more of them. At least LLMs don't call HR on you when you rightfully tell them that they're full of shit. Though.. well. Claude probably might.

LLMs are worse at programming than any dev I've ever worked with. Yes, even $latest_model. They have no understanding or ability to reason, and they make mistakes no human would make. They are, in short, bad at programming.

I've seen developers pushing code repeatedly to car engine firmware with for-loops that weren't even valid C syntax, have yet to see a modern LLM do this kind of mistake

Re: No LLM Code in Dependencies

#97
post #27

Was this done by manually reviewing commit messages? I think it would be interesting/useful to have a tool that could use some basic heuristics about LLM generated code to detect code-blobs even if they are not explicitly called out in a commit message.

Apparently, though not very carefully. The "particularly large LLM generated code churn" in the ram library, for example, is the LLM being used to simply git-revert a change that was not originally done by an LLM.

The commit it reverted has a high probability of also being generated with an LLM, though without disclosing that in the commit message.

Re: No LLM Code in Dependencies

#98
I sincerely hope people taking the side of the LLMs get everything they ever asked for.

When $llm_company begins asking you to open your wallet to fix every vulnerability, bug, or other breaking issue, instead of the guy in Nebraska doing it for free because someone mentored him, will the economics change? Probably not.

Re: No LLM Code in Dependencies

#99

How come all the open source projects are fretting over the copyright status of LLM code but big companies are just vibe coding slop all day for their internal closed source projects without a care in the world?

It's almost like the big companies are playing by a totally different set of rules. How else could Sam, Zuck and co, just blatantly rip pirated, copyrighted, copylefted material and just call whatever repercussions they do (or don't) receive the "cost of doing business". I'm not "anti-AI", I think it's incredible what can be done, but HOW it was produced, and how it's being used is wrong on so many levels.

Spotify is running ads for a design "thing", that's basically a generative AI logo creator. Isn't that one of the few instances that's already been clearly put into law - that you can't copyright AI generated stuff? How can you create a business that's selling uncopyrightable logos (which definitely would need/want to be copyrighted/trademarked)? It's the Wild, Wild West out here.

Re: No LLM Code in Dependencies

#100

This is completely infeasible in the age of mythos. The reality is that the velocity is just not going to feasible from a security PoV without leveraging these tools.

In ten years we'll look at human written code like the unreliable garbage it is, and never rely on anything that wasn't at least seriously looked over by an LLM. It won't be even close.

In ten years we'll be drowning in subtle bugs introduced by the unreliable garbage that is machine-generated code, and the industry will hopefully have learned to never rely on anything that wasn't at least seriously looked over by an actual thinking human being that understands it. We'll look back on our youthful idealism and cultish faith in this new technology with embarrassment.
Post reply on HN