this post was submitted on 12 Mar 2026
28 points (100.0% liked)

technology

24281 readers
160 users here now

On the road to fully automated luxury gay space communism.

Spreading Linux propaganda since 2020

Rules:

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] invalidusernamelol@hexbear.net 1 points 17 hours ago

That bot-to-bot PR is terrifying. A ton of maintainers who inherited old projects are starting to just hand them over to bots.

Some of these projects are upstream dependencies for tons of existing codebases and it's only a matter of time before a bot tells another bot "LGTM" and starts merging code that blatantly steals info. Especially for projects that are known to be part of CI/CD or build tooling that no one ever really looks at.

Another reason to only use the standard library and a small subset of trusted packages that you have audited/follow...