LLVM has introduced rules for the use of AI tools. Curl and Node.js will limit payments for vulnerabilities due to AI.

The developers of the LLVM project have approved the rules for using AI tools in development. The need for regulating AI usage arises from the increasing number of garbage changes proposed for inclusion in the LLVM codebase. By 'garbage,' we refer to changes generated by AI tools and submitted as-is, without understanding the context, verification, or adhering to the stance of 'the maintainer will sort it out.' Such activity creates additional pressure on maintainers and forces them to spend time deciphering useless code.

At the same time, LLVM developers acknowledge that when used properly, AI can be a useful tool that accelerates development. The conditions for using AI approved in LLVM are partly based on the rules published last year by the Fedora project. The main idea behind the adopted rules is that developers should not shift the responsibility for reviewing AI-generated code onto maintainers.

In addition to the mentioned responsibility for submitted changes in Fedora's rules, LLVM has introduced a requirement for mandatory manual review of AI-generated code before proposing a change to the project. Furthermore, the person preparing the change must have a good understanding of the submitted code and be ready to answer related questions. It is recommended to manually write descriptions for pull requests rather than relying on AI to prepare accompanying text.

When submitting a change, a significant portion of which is generated by AI tools, it is necessary to include information about the use of AI in the note of the pull request, such as indicating the tag 'Assisted-by: AI assistant name.' The use of automated AI tools, such as the AI agent @claude integrated with GitHub, which performs actions or submits comments without human involvement, is prohibited.

The adopted rules apply not only to the code in change requests but also to RFC documents proposing new functionalities, reports of vulnerabilities and bugs, comments, and feedback on pull requests.

Additionally, it is worth noting the decision by Daniel Stenberg, the author of the curl utility for transferring data over the network, to discontinue the program for awarding monetary rewards for reporting vulnerabilities in Curl. The rewards will cease at the end of January due to the influx of spam submissions generated by AI assistants and sent without verification of actual vulnerabilities.

It has been reported that in the first two weeks of January, 20 submissions claiming vulnerabilities were made for rewards. An analysis of these submissions showed that none contained real vulnerabilities. Authors of vulnerability reports are advised not to report issues unless they understand the essence of the problem and can reproduce the error. Reviewing such submissions consumes a lot of time for the security team. It is expected that the discontinuation of rewards will reduce the motivation for people to submit spam and poorly vetted vulnerability reports, regardless of whether they are generated by AI or not.

Additionally: The Node.js project also announced restrictions on accepting submissions for vulnerability rewards, now only accepting submissions on HackerOne from high-rated participants who already have experience submitting correct problem reports (signal > 1). The reason for this change is the significant increase in the number of low-quality submissions. Reviewing spam submissions takes time and resources that could be directed toward real work to enhance platform security. From December 15 to January 15, the project received over 30 such submissions.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster