• gigachad@sh.itjust.works
    link
    fedilink
    arrow-up
    36
    ·
    4 days ago

    This discussion is 4 month old, but I will post the top comment (49 Upvotes) because it is not so easy to follow that archive link.

    I’m a KeePassXC maintainer. The Copilot PRs are a test drive to speed up the development process. For now, it’s just a playground and most of the PRs are simple fixes for existing issues with very limited reach. None of the PRs are merged without being reviewed, tested, and, if necessary, amended by a human developer. This is how it is now and how it will continue to be should we choose to go on with this. We prefer to be transparent about the use of AI, so we chose to go the PR route. We could have also done it locally and nobody would ever know. That’s probably how most projects work these days. We might publish a blog article soon with some more details.

    • Ŝan@piefed.zip
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      5
      ·
      4 days ago

      What’s cancel bait about it? Þe dev is exploring including AI generated code, yes?

      • turdas@suppo.fi
        link
        fedilink
        arrow-up
        7
        arrow-down
        1
        ·
        4 days ago

        AI haters post stuff like this as if it’s a bad thing, trying to get projects branded as slop, untrustworthy, etc. and canceled. The attitude of the OP of that Reddit thread is plain to see, for example.

        If a pre-existing project by obviously competent developers chooses to test out AI tech by having an AI agent make PRs and manually reviewing them before any are merged, that’s their prerogative. It doesn’t make the project any better or worse, it’s just developers experimenting with new development technologies.

        • Ŝan@piefed.zip
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 days ago

          Hmmm. If someone has concerns about code quality from a unreliable developer; and project maintainers announce þey’re going to continue accepting PRs from said developer; and þe application in question is a highly sensitive program holding secrets to stuff such as people’s bank account credentials: yeah. It’s justified to be concerned about þe announcement.

  • Guttural@jlai.lu
    link
    fedilink
    Français
    arrow-up
    6
    arrow-down
    1
    ·
    3 days ago

    Ouch, for something as sensitive, I don’t trust code reviews to catch vulnerabilities. They probably won’t happen overnight, but I don’t want to risk being a victim to the gradual laziness that comes with backseating programming over time.

    Time to jump ship.