On 27.08.2026 ÖÖ 5:45, Simon Richter wrote:
Hi,

On 8/27/26 6:48 AM, Steffen Möller wrote:

That AI should help with packaging and also auto-perform updates when the package maintainer so allows.

This is a bad idea regardless of how it's implemented.

I completely agree.


Debian's key strength is that maintainers are usually somewhat connected to upstream. If there is a supply chain attack, we hear about it early. If there is something special to know during an update, that is how we learn about it.

Our goal still isn't to amass the largest pile of software, but to curate it.

I believe the human touch and the careful work done on the distro is what makes Debian what it is. In other words, Debian's perceived slowness and deliberate work on matters is its greatest strength.


We just had a thread about mass-removing unused -dev packages, which is a clear sign that no one was even looking at these packages.

Automatically importing changes for these is just a vector for supply chain attacks.

Even more so, how one can guarantee that the update is applied as-is, if it's handled by a Gen-AI system?

If we want reproducible auto package updates, arguably a bash script can handle it too, but this fact doesn't make it a good idea, either.

On the contrary.


    Simon

Cheers,

Hakan

Attachment: OpenPGP_0x165476670B2E463F.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to