2026-08-31 01:55 UTC
Replies (1)
-
@lina@neuromatch.social 2026-08-31 01:55
You may have caught that the new policy requires that PRs are submitted by humans. In both the policy and the AGENTS.md, they make it clear that "only human beings can ever be credited within commit messages." This is enforced with a GitHub action that checks for commit authors containing (aider|anthropic|claude|codex|copilot|devin|gemini|grok|openai) ... so people actually named Claude or Devin get flagged as policy violators by a failed action, as do people with an email containing "raider" and people working for ngrok and using a company email. 🤪 https://github.com/lxc/incus/blob/main/.github/workflows/commits.yml#L18-L46 This effectively implements a "don't ask, don't tell" policy for LLM use. While the policy does discourage "unguided use of [LLM] tools" and states that "inability to prove understanding of the code contributed will result in a loss of trust in that contributor by project maintainers which can then lead to exclusion from any further contribution to the project", this policy also obscures which contributions involved the use of LLMs. This might explain why I didn't notice the policy change sooner, and why I haven't seen anyone posting about it. One of the most immediate indicators of potential vibecoded contributions is the warning message at the top of a GitHub repo when a user you've blocked has been included as a commit author. This also means that we have to assume that LLMs have been used since at least June 16th when the policy change was committed. Where obscuring the fact that your contribution was vibecoded was a bannable offense in the previous policy, it's now the recommended way to vibecode. It seems that this approach is intended less as a way to obscure LLM contributions and more as a (likely flimsy) legal maneuver to avoid potential liability related to licensing, given that it's a legal grey area. Nonetheless, the issue remains. 4/