Rendered at 10:18:12 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
bmitch3020 2 days ago [-]
Compared to the current state, where multiple "security researchers" independently send unsolicited identical reports, this feels like the right solution:
1. It's opt-in, anyone that doesn't want to receive these reports, or has reasons to not want AI used on their project gets that by default.
2. It's free for OSS projects, many of us won't spend money for a hobby we work on in our spare time and give away.
3. The reports go back to the maintainer, and not to potential attackers.
I would like to see more locally run models in this space, breaking the dependency on SaaS vendors. Even though those local models can't be controlled and would therefore be used by attackers. At some point, we'll get past this wave of newly discovered issues that have been lurking in the code for years, and the scans should run like any other linter or dependency checking tool.
1. It's opt-in, anyone that doesn't want to receive these reports, or has reasons to not want AI used on their project gets that by default.
2. It's free for OSS projects, many of us won't spend money for a hobby we work on in our spare time and give away.
3. The reports go back to the maintainer, and not to potential attackers.
I would like to see more locally run models in this space, breaking the dependency on SaaS vendors. Even though those local models can't be controlled and would therefore be used by attackers. At some point, we'll get past this wave of newly discovered issues that have been lurking in the code for years, and the scans should run like any other linter or dependency checking tool.