Comment on Do you actually audit open source projects you download?

<- View Parent
notabot@lemm.ee ⁨5⁩ ⁨days⁩ ago

‘AI’ as we currently know it, is terrible at this sort of task. It’s not capable of understanding the flow of the code in any meaningful way, and tends to raise entirely spurious issues (see the problems the curl author has with being overwhealmed for example). It also wont spot actually malicious code that’s been included with any sort of care, nor would it find intentional behaviour that would be harmful or counterproductive in the particular scenario you want to use the program.

source
Sort:hotnewtop