On Mon, Jul 27, 2026 at 02:26:17PM +0100, Ian Jackson wrote:
> Lucas Nussbaum writes ("Re: GR: Ban LLM contributions from Debian"):
> > I recently produced two concrete cases that might be worth considering
> > to help define what (4.) should say.
> 
> I feel you are trying to pick at edge cases.  This is not a fruitful
> thing to do.  Inevitably there will be edge cases, and they will be
> handled by the relevant decisionmakers in Debian making judgement
> calls.
> 
> Having said that. your first two examples are the kind of thing I am
> trying to prohibit, and I think that I can be reasonably confident
> that (if my option wins) the Community Team (say) would see it that
> way.
> 
> I should say that I have not read any of the things you refer to.  I
> am relying on your descriptions.  I regard LLM output as an infohazard
> - a kind of pollution, that it is dangerous to interact with.

This attitude is a problem, because it makes you not understand why your
proposal would not be workable.

You are saying that you would refuse to look at the report when someone 
reports an exploitable vulnerability in dgit or Arti or tag2upload that 
was found with LLM assistance.

Your GR text and reply to Lucas are saying that sending bug reports or
emails reporting security vulnerabilities to Debian maintainers would
be CoC violations, or at least on the edge of CoC violations.

If you would read the second example from Lucas with the vulnerability 
(#1142332), then you would understand why finding and reporting security
vulnerabilities without any LLM assistance is going the way of the dodo.

> Ian.

cu
Adrian

Reply via email to