Hi,

On Thu, 2026-07-23 at 10:45 -0400, Theodore Tso wrote:
> > The scope of this GR is (non-exhaustive):
> > - Debian source packages
> > - Official Debian project software, such as lintian
> > - Debian web resources
> > - Documentation and translations added by Debian contributors
> > - Official communication from Debian
> > 
> > It does not include:
> > - Upstream projects using LLMs for development
> > - AI-related software
> 
> What if there is a security fix which is applied upstream, which is
> then cherry-picked into the Debian sources to fix a high-criticality
> CVE?  In that case, the patch is in the debian source package (for
> example, in debian/patches/...).
> 
> Suppose a Debian developer uses an LLM to fix a high-criticality bug,
> and sends the fix upstream, but in the meantime it's in the Debian
> sources.
> 
> Or suppose a Debian developer uses an LLM to fix bug which is causing
> the Debian web site to be dead.  Does this GR disallow all of these
> scenarios?

You could add "a Debian contributor uses a LLM to find a highly
critical bug in Debian's software and/or infrastructure" to the list.

I guess the GR would forbid submitting or acting on such reports? Would
we just leave the hole open?

Note that LLMs seem pretty good at this task, better than many
humans...

Ansgar

Reply via email to