All of lore.kernel.org
 help / color / mirror / Atom feed
From: Sam James <sam@gentoo.org>
To: "Michał Górny" <mgorny@gentoo.org>
Cc: distributions@lists.linux.dev
Subject: Re: Looking for advice on how to deal with potential slop packages
Date: Wed, 11 Mar 2026 02:50:59 +0000	[thread overview]
Message-ID: <87eclrw030.fsf@gentoo.org> (raw)
In-Reply-To: <a3f792e918674e208492a077679ae6ffc88ce0c9.camel@gentoo.org>

[-- Attachment #1: Type: text/plain, Size: 2251 bytes --]

Michał Górny <mgorny@gentoo.org> writes:

> Hello, everyone.
>
> Seeing more and more packages embracing LLM-driven development (to the
> point of "vibe coding" or slopware), I'm looking for your ideas on how
> distributions should deal with that.  I'm basically torn between three
> things:
>
> 1. My duty towards the users to deliver up-to-date versions of software.
>
> 2. My duty towards the users to deliver *good* and *secure* software.
>
> 3. My ethical concerns, both directly related to LLM use, and to what
> people are using them for.

For those interested, we've started discussing it on the Gentoo side at
https://public-inbox.gentoo.org/gentoo-dev/fd8fea8a469a11e302dfd66dad76bbfa230198cf.camel@gentoo.org/
now too.

> [...]
>
> What are your experiences, thoughts and ideas how to deal with this?  I
> mean, staying on old software versions and hoping people will change
> their minds (or more precisely, LLMs will stop being subsidized and
> people will have to start paying serious money for their usage) is not
> exactly a good idea.  Going around and telling people "please switch
> from dependency X to Y because X is slop (and Y isn't yet)" doesn't
> sound like the best use of our time either.  And forking?  With the
> depressing state of FLOSS these days, I can't even find energy to
> maintain my own projects, let alone take anything else.
>

You know my position on this but saying it here for the benefit of the
list: I think some collaborative effort is needed just like we ask
people to port away from unmaintained dependencies or something that is
otherwise broken. chardet has an alternative AFAIK:
charset-normalizer. And we can lobby upstreams to not depend on new APIs
introduced only in "infected" versions.

Of course, that's still work, and I'm very tired of all of this already
too.

>
> [1] https://wiki.gentoo.org/wiki/Project:Council/AI_policy
> [2] https://github.com/crossbario/autobahn-python/issues/1716
> [3] https://github.com/crossbario/autobahn-python/issues/1735
> [4] https://github.com/crossbario/autobahn-python/issues/1782
> [5] https://github.com/crossbario/autobahn-python/discussions/1818
> [6] https://github.com/chardet/chardet/issues/327

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 418 bytes --]

  parent reply	other threads:[~2026-03-11  2:51 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-03-07 10:38 Looking for advice on how to deal with potential slop packages Michał Górny
2026-03-07 12:07 ` Noé Lopez
2026-03-07 12:36 ` Morten Linderud
2026-03-07 15:31   ` Simon Josefsson
2026-03-08  4:00     ` Guillem Jover
2026-03-22 23:53     ` Andreas K. Huettel
2026-03-23  8:14       ` Simon Josefsson
2026-03-11  2:48   ` Sam James
2026-03-11  2:50 ` Sam James [this message]
2026-03-27  8:01 ` Bernhard M. Wiedemann

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87eclrw030.fsf@gentoo.org \
    --to=sam@gentoo.org \
    --cc=distributions@lists.linux.dev \
    --cc=mgorny@gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.