- cross-posted to:
- technology@lemmy.world
- cross-posted to:
- technology@lemmy.world
Considering AI generated code is public domain, so not exactly open source licensed, this is a good move.
I applaud this at least in theory. As others have pointed out this may prove thorny to implement. But, I love the sentiment and hope it goes well for them.
Yeah, this makes sense. They won’t be able to kick every vibecoded project off, but it gives them a rule to point to when they do find and remove slop.
Some of the commenters on the Codeberg issue are expressing concerns about copyright status, but my main concern is security issues with these projects, which I have expressed before. Somebody vibecoded a script to sort files? I don’t really care.
Someone vibecoded a network facing application, shipping a docker container, and is trying to encourage people to deploy it? If I investigate, and see the bad security practices common to vibecoding, I wouldn’t want to be providing that for people to download. Even though I’m technically not responsible for it, it just doesn’t feel right to host something that could explode later. I would want to be able to take it down, and having a rule to point to prevents complaints when Codeberg does so.
while I agree with the sentiment. what if someone just sloppily hand-coded an insecure docker container, should you be able to kick that off too? I fear security isn’t a good baseline to decide if a project should be hosted because security is a gradient and it becomes very subjective to say what constitutes secure. following that, would you give remediation opportunities for hand-coded insecure projects? It’s a can of worms.
I would argue that they can argue it purely from a capacity perspective.
They can estimate the scale of handwritten code growing over a period of time, but not the scale of AI written code scaling, meaning their platform cannot anticipate the scale and therefore it is unsustainable. And at that point the scale of security awareness as a whole can be considered, e.g. “how many attack surfaces, e.g. repos, are we hosting?” vs “how many of our repos are insecure?”
what if someone just sloppily hand-coded an insecure docker container, should you be able to kick that off too?
I can talk to them and have them fix it without them being weird about it. But if they don’t understand the poor design decisions in the first place then I have no confidence won’t be able to actually fix it, and keep it fixed in the future.
It’s fuzzy, and many generalizations are gonna be made.
Ultimately, it really comes down to human judgement and not your instance not your rules. They are hosting for free. They don’t have any obligation to host your projects. The rules and everything are nice conventions, and a good attempt at transparency, but at the end of the day, there is someone with access to the admin panel who is going to make the decisions, and you’re not really going to be able to do anything about them.
It’s the same thing with lemmy tbh, although it’s less annoying because it’s much easier to self host and migrate to Forgejo, as opposed to hosting Lemmy. That’s why I phrased it as “I would feel uncomfortable hosting this content” rather than trying to address the fuzzier arguments about the necessity of human judgement, the difficulty of detecting LLM generated code, or the possibility of incorrectness.
Some good questions in the comments:
What does “written by” mean? Who defines authorship? What does “mostly” mean? Who defines ratio? Is this going to be enforced in practice? Who is going to enforce it? Based on which reporting?
Seems reasonable but good fucking luck enforcing that.
IMO they should instead simply charge cost price for hosting. It can’t be much surely?
I don’t think the cost of hosting the repositories itself is the issue, more the legal problems and the fact that real projects get drowned out by the noise
How the hell does a user see a voting like this? I’m using Codeberg for quite a while and reading here something like “vote closed” is weird to me.
Now I’m not talking about the content of the core itself here.
Are you a member of Codeberg e.V.? Votings are exclusive to members AFAIK, and get announced via mail.
Correct. Membership to the nonprofit Codeberg e.V. is 24 Euro a year (potentially less if you request a discounted rate and are approved). You will be supporting Codeberg’s mission and can optionally take part in these discussions and votes. There is an organization on Codeberg you’ll be added to where discussions occur and then vote notifications are sent out by email.
See also: what is codeberg e.V.?
deleted by creator
Let’s discourage user transparency and AI disclosure
OMG that’s a great move.
You can’t just make murder illegal! All you’ll do is make people lie about doing it!
THIS.
All my murderer friends have moved their activities to jurisdictions where murder is allowed or tolerated.
I think CodeBerg should push for giving Vibe Coders the death penalty, to make sure deterrence will work.
Should users who don’t self-host start recording themselves while coding just as a precaution, in case their host will ask for evidence of work authenticity?






