frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

OpenAI and Hugging Face address security incident during model evaluation

https://openai.com/index/hugging-face-model-evaluation-security-incident/
1178•mfiguiere•14h ago•816 comments

Kimi K3 Is Competitive with Fable; Kimi K3 and Fable Is SoTA

https://fireworks.ai/blog/kimik3-fable
640•piotrgrabowski•11h ago•348 comments

Intel Starts Shipping High-NA EUV Silicon

https://morethanmoore.substack.com/p/intel-starts-shipping-high-na-euv
80•zdw•3d ago•17 comments

Original Apollo 11 Guidance Computer source code for command and lunar modules

https://github.com/chrislgarry/Apollo-11
82•noteness•5h ago•22 comments

Introduction to Formal Verification with Lean Part 1

https://hashcloak.com/blog/tutorial-introduction-to-formal-verification-with-lean-(part-1)
22•badcryptobitch•2d ago•0 comments

Advertise in ChatGPT

https://ads.openai.com/
778•montecarl•15h ago•572 comments

FreeInk: Open ecosystem for e-readers

https://freeink.org/
566•FriedPickles•15h ago•122 comments

Judge approves $1.5B Anthropic settlement for pirated books used to train Claude

https://apnews.com/article/ai-anthropic-copyright-settlement-claude-books-bartz-74b140444023898ae...
375•BeetleB•15h ago•312 comments

Late.sh – a command-line Clubhouse for computer people

https://late.sh/
175•itherseed•7h ago•62 comments

Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber

https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flas...
693•logickkk1•19h ago•530 comments

Codeberg: ToU extension to prohibit LLM-extrusions

https://codeberg.org/Codeberg/org/pulls/1253
8•robin_reala•1h ago•5 comments

A digestion of the Jacobian conjecture counterexample

https://terrytao.wordpress.com/2026/07/21/a-digestion-of-the-jacobian-conjecture-counterexample/
263•jeremyscanvic•13h ago•98 comments

Show HN: A new kind of FPS aim trainer

https://openaim.pramit.gg/
51•pmazumder•4h ago•27 comments

Ten Steps Towards Happiness (2015)

http://hintjens.com/blog:99
136•emerongi•9h ago•50 comments

Long presumed dead, a thriving coral reef is discovered in West Africa

https://e360.yale.edu/digest/benin-coral-reef
350•speckx•18h ago•75 comments

"Drawing" the Mona Lisa with GPT-5.6, Claude, Gemini, and Grok

https://www.tryai.dev/blog/ai-drawing-arena-colored-pencils-claude-gpt-grok
200•hershyb_•13h ago•74 comments

Jack Dorsey launches Buzz to combine team chat, AI agents and Git hosting

https://runtimewire.com/article/jack-dorsey-block-buzz-team-chat-ai-agents-git
321•ryanmerket•17h ago•274 comments

Apple defeats liability for not scanning iCloud for CSAM

https://blog.ericgoldman.org/archives/2026/07/apple-defeats-liability-for-not-scanning-icloud-for...
418•speckx•19h ago•398 comments

It's a shame what's happened to radio

https://blog.jimgrey.net/2026/07/21/its-a-shame-whats-happened-to-radio-3/
113•sonicrocketman•10h ago•104 comments

Atomically Thin Materials Significantly Shrink Qubits

https://spectrum.ieee.org/2d-hbn-qubit
8•Jimmc414•4d ago•1 comments

LG to ban residential proxies from smart TV apps

https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/
280•DemiGuru•8h ago•267 comments

ScreenWall – Turn old phones into synced widgets for your space

https://screenwall.app/
26•buibuibui•4d ago•7 comments

Laguna S 2.1

https://poolside.ai/blog/introducing-laguna-s-2-1
322•rexledesma•17h ago•60 comments

Map of the world's great castles and fortresses

https://thecastlemap.com/
259•marklit•18h ago•163 comments

Gemini last models: temperature, top_p, and top_k are deprecated and ignored

https://ai.google.dev/gemini-api/docs/latest-model
90•greatgib•12h ago•29 comments

'VPNs are lawful technical tools,' says EU Court in landmark copyright ruling

https://www.techradar.com/vpn/vpn-privacy-security/vpns-are-lawful-technical-tools-says-eu-court-...
566•healsdata•14h ago•98 comments

Show HN: Justif – Knuth-Plass justification and microtypography for the web

https://justif.lyall.co/
160•lyall•4d ago•28 comments

Show HN: ReadKinetic – a free, local-first speed reader for your own books

https://www.readkinetic.com/app/
82•SamuraiLion•4h ago•40 comments

I graded 36 popular MCP servers on agent usability. A third got a D or F

https://tengli.dev/posts/mcp-servers-failing-agents.html
14•tengbyte•4h ago•2 comments

My USB Drive Has a Hidden Encrypted Vault

https://rootkitlabs.com/2026/06/22/I%27m-Building-a-Secure-USB-Drive/
237•machinehum•2d ago•139 comments
Open in hackernews

Codeberg bans vibe coded projects

https://codeberg.org/Codeberg/org/pulls/1253#issuecomment-19820434
82•ambigious7777•2h ago

Comments

saidnooneever•1h ago
i wonder how they will detect it though. is there some good tool to tell them if code files someone submit were outputs or altered by LLMs?
Vivek-KY•1h ago
even i wonder,its hard to detect it.
guessmyname•1h ago
Most people leave the “Co-authored-by: <name>” lines in their Git commits [1]. I’m not sure why exactly, but I suppose it's either laziness or a lack of care. Regardless, if I were Codeberg, that would be the first thing I’d detect, and then I might use a Random Forest Classifier to identify the rest.

[1] https://docs.github.com/en/pull-requests/how-tos/commit-chan...

prennert•1h ago
honesty?
applfanboysbgon•1h ago
AGENTS.MD and CLAUDE.MD also provide easy detection avenues. Trivial measures will probably catch 70-80% or more. You don't need a 100% enforcement rate for a rule to exist, indeed there are basically no rules anywhere in the world that achieve that.
ramon156•59m ago
Then the linux repo is also banned. I don't think that's a good way to detect "vibe coding"
mattashii•56m ago
Whilst they may provide a strong signal, I wouldn't call it a guarantee. If I wanted to avoid vibe-coded contributions I might add such files, but with instructions for the agents that they're not allowed to read or touch any of the files in the repository.
Mashimo•53m ago
But that just means they probably used AI to help code, not that it is vibe coded, no?
K0nserv•1h ago
I feel it's a faux pas to pass off work entirely or partially done with AI as your own. I make sure I leave those lines in specifically for that reason.
raesene9•56m ago
As other have mentioned, and I'm the same. Leaving "Co-Authored by:" feels like open disclosure of how the project was created.

That way if a consumer does not want to use LLM generated/assisted software, it's easy for them to do that without having to search around in the codebase for "AI Tells".

Removing those would feel like I was mis-representing my coding abilities (LLMs are better at most coding than I am) :)

adisguy•1h ago
It's rare to see terms of use that are all actively enforced. I think it makes sense to state the outlines to justify e.g. banning a user, or in potential legal matters (IANAL, just assuming).
OleksandrC•54m ago
Claude-written code is quite easy to spot - because it has this particular style of overly verbose "walls of text" comments, that 1. repeat verbatim what the code just below does, 2. include "list of things" that quickly go stale, 3. talk about "how things used to be before we changed it here" (useless to anyone reading the code now), 4. "talk to reviewer" in comments. And many other comment sins.

And even if you tell it to make it leaner, it'll maybe trim a little, but it'll still be a wall of text. Claude really likes to write its opuses and fables in comments.

And commit messages suffer from the same verbose prose.

And all of that happens even if you explicitly instruct in CLAUDE.md to keep things lean/concise. It's a disease.

timjver•51m ago
That doesn't really answer the question of how they're going to detect it at scale. Ban repositories with long comments?
OleksandrC•43m ago
They could, for example: 1. Rely on users flagging suspected repos (with human moderators reviewing afterwards). 2. Deploying AI agents to evaluate repos against known AI-generated-code patterns (also with human moderators afterwards). Of course, the irony of the situation - using slop machines to fight slop.
ande-mnoc•30m ago
It’s very poetic that codes written without human efforts can be efficiently dealt without human efforts.
themgt•40m ago
Claude-written code is quite easy to spot - because it has this particular style of overly verbose "walls of text" comments, that 1. repeat verbatim what the code just below does, 2. include "list of things" that quickly go stale, 3. talk about "how things used to be before we changed it here" (useless to anyone reading the code now), 4. "talk to reviewer" in comments. And many other comment sins.

"quite easy to spot" this style in what sense? To a human? To an LLM? To a deterministic code scanner you wrote by hand yourself, per Codeberg policy?

flohofwoe•41m ago
I'd guess that it only matters once shit hits the fan (e.g. a copyright dispute or license violation). E.g. when the project owner claims that he wasn't aware of the violation because LLMs wrote all the code, Codeberg can simply point to the terms of use before deleting the project, which from their point of view is a quick and clean solution to the problem.
winstonwinston•41m ago
For starters they (those who submit) should not hide the fact. If they do, it is quite obvious to spot LLM generated code for anyone competent.
IceDane•1h ago
Well, that's their prerogative, I guess. But the burden of proof will be on them, of course. They can't expect users to prove a negative. There are simple tells that would reveal a lot of projects. Claude Code's moronic defaults of littering commit messages with both a CC author trailer as well as a session link will reveal some, but those are easy to disable. Then there is stuff like prolific comments, em-dashes in comments, etc.. but none of those are real proof that a project was built with agents.

Either way, I was never interested in codeberg and this just means that I'm less interested.

account42•49m ago
There is no burden of proof for them as they have no obligation to provide a service to anyone.
joegibbs•39m ago
That legalistic "I can do whatever I want as long as it's not breaking the law" argumnet lasts until the first time they ban wrongfully ban someone for it and get huge negative PR
jeroenhd•32m ago
The support they will receive for banning slop will probably outweigh the negative press for a false positive.
jaggs•1h ago
I'll add my comment from a previous thread:

This is a bit strange. Are they saying that Codeberg no longer accepts vibe coded projects at all?

If so, it seems kind of short sighted. Within a very short period of time all code will be AI code. What then?

And as the models improve, along with better code will come better bug fixing etc etc. So the quality of AI code will absolutely surpass that of human code. What then?

Will the repositories demand proof of programming ability? Why, when AI will be handling everything anyway. It would be rather like driving schools mandating that all drivers can strip an engine before they're allowed to drive? Very odd.

awesan•1h ago
It's not strange to ban chess computers at a chess tournament, and it's equally not strange to ban AI code on a code hosting platform.

The costs involved with hosting a bunch of vibe coded stuff that no one is really invested in or cares about would undermine the mission of Codeberg, so it makes sense for them. Other code hosting platforms can go a different route.

applfanboysbgon•1h ago
I suppose, if your completely insane fantasy ever becomes reality, they could simply reverse the policy. Codeberg currently lives in the real world, not your fantasy world, so it makes sense to determine policy based on the state of the real world.
jddj•1h ago
It would be rather more like driving schools disallowing autopilot.

Not to say that I agree that the metaphor makes sense here in the first place

thih9•
CodesInChaos•58m ago
How do they define "vibe coded"? I believe "vibe coded" was originally defined as letting AI write code without human review. But I often see it used for all AI assisted code.

edit: Looks like they don't talk about "vibe coding" at all, but ban code mostly written by AI:

> You must not share projects that mostly consist of code written by "generative AI"-tools

marginalia_nu•57m ago
Surprising to find a comment thread full of vibe coders being extremely defensive.
jjgreen•47m ago
Depressing rather than surprising.
Antibabelic•41m ago
Sarcasm?
lionkor•39m ago
Unsurprising given that a large amount of posts on the front page are about or in support of projects that are entirely vibecoded with near zero human input beyond "hm it feels kind of slow, make faster?".

AI is used to launder a lack of care and skill, and people really love not caring and not having to put in any work.

jeroenhd•34m ago
One has to wonder how many of these vibe coding accounts are being defensive themselves, rather than having their LLMs be defensive for them.
alfiedotwtf•56m ago
Anyone else feel like this is pushing shit up a hill?
sajithdilshan•56m ago
In a way it make sense. I don't think they have the capability/money to scale out the system to support a plethora of vibe coded project like Github does.
serchinastico•36m ago
Especially being a non-profit, and a free product.
cedws•56m ago
I'm tired of SlopHub but at the same time how do you realistically ban vibe coding? This will cause a bunch of infighting with people accusing each other.
feverzsj•54m ago
GOOD! Now I'm seriously considering moving to coderberg. Their website is also 10 times faster than github already.
witx•39m ago
I already did move everything there. The responsiveness is great.

I only keep github as a front to showcase projects I want for CV reasons but I host no code there

LtWorf•18m ago
I marked all my project on github as closed and added a link to the codeberg one.

After years google will still link to github anyway.

I had thought of just keeping them open and sync them, but I thought in that case people would presume the project is actually active on github and try to interact creating issues and pull requests and getting frustrated.

I must say codeberg's reliability isn't the best, but with all the scrapers that hit them it's a miracle they do seem to manage. And at work things on our private network without scrapers aren't more reliable.

RicoElectrico•54m ago
My hypothesis is that this particular kind of AI pushback originates from people who really are terminally online and can't separate their job (programming) from free time (also programming). Programmers are unusual in that regard, compared to most other professions.
KingOfCoders•54m ago
What is a vibe coded project? Where does it start? Cursor autocomplete? One shot Github project copies?

[Edit] The pull link is https://codeberg.org/Codeberg/org/pulls/1253/files and says

"7. You must not share projects that mostly consist of code written by "generative AI"-tools (including services such as Claude, OpenAI Codex). Such projects having an unclear copyright status (see requirements § 2 (1) 1 and § 2 (1) 3) and furthermore have little safeguards to ensure that they do not include harmful code (c.f. § 2 (1) 5)."

Whatever "mostly" means. If you autocomplete a lot, and the code written is "mostly" written by AI by autocomplete - it seems you fall under this.

I wonder what the ratio needs to be. And I wonder if auto-refactoring in Intellij is also included, because Intellij created the code and then also has "unclear copyright status" if we follow the logic.

Together this opens up more questions to me than it answers.

Mashimo•51m ago
> projects that mostly consist of code written by "generative AI"-tools

I guess if you auto complete line by line and actually read the code it should be gucci.

Edit: Oh, you found it as well now. Disregard my post.

KingOfCoders•45m ago
"I guess if you auto complete line by line and actually read the code it should be gucci."

Not from their wording.

cwillu•51m ago
“You must not share projects that mostly consist of code written by "generative AI"-tools (including services such as Claude, OpenAI Codex).”

Seems pretty clear to me?

exploderate•54m ago
They are a non-profit with a mission to support free software:

https://codeberg.org/Codeberg/org/src/branch/main/en/bylaws....

However, they do this because of copyright status and harmful code:

"7. You must not share projects that mostly consist of code written by "generative AI"-tools (including services such as Claude, OpenAI Codex). Such projects having an unclear copyright status (see requirements § 2 (1) 1 and § 2 (1) 3) and furthermore have little safeguards to ensure that they do not include harmful code (c.f. § 2 (1) 5). "

jorisw•49m ago
So 'mostly' is the clearest they get here. Meaning more than 50% of lines of code? At any given time?
lionkor•31m ago
This makes sense from a copyright perspective -- as long as you maintain 50% or more actual human authorship, in case of a conflict with future copyright laws around LLM generated code, you can at least claim that a majority of the code is human-authored.
mmoustafa•53m ago
How do you define vibecoding? Is using LLM-assisted autocomplete vibecoding? Is editing single files via an LLM vibecoding? When do we cross the threshold?

Just saying mostly written by generative AI is extremely broad as that can happen even with “human written” codebases via AI-assisted tools.

lazzlazzlazz•52m ago
Are they also banning projects whose code was written with AI or just vibe coded projects? Roughly every serious codebase now and forevermore will be at least mostly AI written.
lionkor•44m ago
> Roughly every serious codebase now and forevermore will be at least mostly AI written.

There is a difference between AI written and AI authored, somewhat. Or maybe call it written vs designed.

A lot of the code written today is written by AI, even in serious projects, but the difference is that serious projects don't vibe code. They don't let the AI write whatever it thinks is best, they instead have clear requirements, established architecture, established testing frameworks, tests, CI/CD, linting and human code review.

The difference is intent; if you use AI to write the code you would have written, then nobody can tell, and it's still fully your code and you have reviewed it. That's not vibe coding.

If you let an agent autonomously plan and write code, that's different. The autonomous "Jesus take the wheel" approach results in code you wouldn't have written yourself, and might also have clear AI tells, fundamental issues (like security flaws by design, performance flaws by design, correctness flaws by design, and general maintainability issues).

This matters. I doubt anyone wants to use or read projects done the latter way.

lilerjee•52m ago
Good job

But how to check which projects are vibe coded?

code-blooded•45m ago
I've actually been thinking it'd be nice to have something like GitHub, but only for hand-written code. If anything, for now I'd like to learn primarily from and perhaps contribute to projects that have human involved at all stages.

But I don't think it will be easy to detect AI written code especially with frequent releases of new models.

voidUpdate•40m ago
It also creates a perfect set of training data for future LLMs
code-blooded•35m ago
It does and it's unfortunate. Perhaps Codeberg might try to block AI crawlers access to the entire website. I know it's all jazz nowadays, but I'm not in favor of using other's people work to train AI without explicit consent.
andy99•51m ago
This appears to be mostly due to fringe / activist views about copyright, rather than anything to do with quality or principle. If it was the latter I could get on board, as in instituting some standards against slop. But in reality it’s just letting activists hijack with their agenda.
account42•46m ago
Fringe / activist views about copyright pretty much describes open source / free software so why do you think that is an argument against doing this?
cwillu•44m ago
The discussion doesn't appear to have been in public at all; all there is on the linked issue is a bunch of first-time posters who wouldn't have been able to vote.
noosphr•43m ago
All vibe coded projects are in the public domain by definition.

The question is if the massive copyright infringement that all the major labs engaged in means that all work derived from llms is under the copyright of the original owners of the work.

It is quite possible to keep track of what piece of training data changed the value of what weight to the point that the activations for any piece of code can be attributed back to the original copyright holder, including the random initial values which are public domain. I've done this on a toy project for gpt2.

witx•41m ago
That's just open source and software freedom views though
trentor•51m ago
Maybe a bit petty but I am fine with it their infrastructure really struggled in the last few months.
TacticalCoder•49m ago
I'm all for banning vibe-coded projects because they are pure turds but I'm not for banning a codebase where AI is used to make the codebase better.

So what's the definition of a vibe-coded project?

I verify the code the latest SOTA/frontier models I pay for do generate and although I daily facepalm myself several times per day, it's still a tool allowing me to be more productive. That's why I've got countless examples of mediocre output to give: if people were to take a look, they'd notice the same.

The problem is the mindset "it runs, hence it's good" of fully vibe-coded crap.

I'm talking about stuff like "Add this information on the webpage next to that other info" and the model going on a tangent and pulling in new libraries to then do a computation on the server-side and then using client/server communication to send the info to then display it.

It works. It did what I prompted. We've got intelligent machines in 2026. Yay!

Except all that nonsense was totally unnecessary and the information was already on the client and all that was needed was to display it.

But the model saw a pattern: can you believe that? A pattern of information being exchanged between the client and the server. So of freaking course my prompt had to be solved by following the same pattern.

So what's that about? Full AI ban or ban of fully AI-generated turds? I'm all for the later but don't ban everything: AI can produce acceptable stuff at a rate that's making it a productivity enhancement tool.

Models have also only been getting better and better: as of 2026 fully vibe-coded projects are pure turds but what about 2028? 2030?

It's not because these things are introducing bugs in every five line of Bash code they write and generate what looks like an infinite amount of slop to solve things which should have required 1/10th of code that it's always going to be like that.

AyanamiKaine•47m ago
It seems the conflict between LLM/AI and programmers is getting hotter and hotter by the week. I wonder where all of this will lead. Our times are uncertain. Many people believe with certainity the future. But only one will come true.
flohofwoe•32m ago
> But only one will come true.

Eh, if this would be true than we would have arrived at a single religion, a single language, a single economic system or a single political ideology. Reality is the opposite, ideas tend to diverge instead of converge.

E.g. the 'agentic engineering believers' will just be another tribe in the jungle.

rarisma•46m ago
Baffling.

Why are they the arbiters of what is made? Also does this break s230?

witx•42m ago
They are arbitrers of what projects they allow hosting on their servers. What's baffling about that?
LtWorf•41m ago
Create your own server and pay for it and they won't have anything to say about what you do with it.
jeroenhd•30m ago
I don't think American laws such as s230 apply here, as Codeberg is German.

If you want to be the arbiter of what you make, throw an instance of https://forgejo.org/ online. It's practically the same as Codeberg except you get full control.

peter_retief•43m ago
wow this is murky water, I love the abstraction of AI, I feel like the director of an orchestra creating beautiful music in code.

I always resented having to write the same code over and over, now automated by AI

but also support free and open software, as all knowledge should be

flohofwoe•39m ago
> I always resented having to write the same code over and over,

Those problems had been solved in the 1970s and don't need LLMs. One solution is called 'copy-paste', another 'software libraries/components' ;)

peter_retief•18m ago
Neither really solved the problem, reality is too nuanced, AI fills the gap.
flohofwoe•15m ago
Not sure if a non-deterministic copy-paste is really filling a gap ;)

But yeah, there are areas in software development where AI assistence is actually useful, I just see code-generation as one of the less useful areas, since tbh this isn't a problem that needs urgent solving. IMHO LLMs are much more useful for passively analyzing/bugscanning code bases (or data in general).

lionkor•16m ago
> I love the abstraction of AI

Careful with that wording. LLMs are not an abstraction, they do not provide an abstraction, not in the software sense, as they are completely non-deterministic the way they are used today. Saying "write me a function that does xyz" is not an abstraction layer ontop of writing it yourself.

sirnicolaz•38m ago
vibe-coders should be pretty happy about the fact that places like this exist, given that's it's ultimately thanks to non-vibe-coded OSS that LLM can improve.
brainless•38m ago
This is good and I am saying this as someone using coding agents full on.

I am a software engineer and I do use coding agents and I do believe that there can be spaces which do not encourage or allow projects built by generative AI.

Detection may become harder as time passes by but that aside, I think the massive generation abilities of multiple LLM providers will simply make it tough for code hosts. But it is also a choice - there should be spaces where people post projects that they actually write by hand (or with minimal assistance of agents).

I am personally and professionally very much on the "generate code" side of the situation simply because I can deliver things faster. But I know that LLMs are basically large word prediction systems that have been built on existing knowledge. They remix very well but I do not think they create brand new algorithms. For someone like me who is focused solely on building ramen-profitable products or services, LLMs are great but I know that I am not going to spend time/effort in any new research. I am not saying that every hand-written project is going to innovate but we should encourage spaces to maintain the barrier, else we may even become complacent.

frabcus•38m ago
Germany copyright law feels like the relevant thing here - Codeberg is a non-profit based in Germany.

Best quick English language overview of status that I could find: https://www.twobirds.com/en/insights/2026/germany/when-can-a...

It looks like Codeberg want only copyrighted material in their service, so it is reliable in the future that e.g. licenses must be followed (e.g. GPL), and copyright doesn't suddenly get declared as being of the model owner, and it isn't a copy of something else.

That is a cautious reasonable position - in early days of LLM coding (3 years ago!) indemnity from model companies was a major issue globally because of the lack of clarity of the law around this. The US specifically has settled on it being (effectively?) public domain. But I don't think that is fully settled, and it certainly isn't settled in international copyright law.

The goal of the vague "mostly" in the Codeberg change is to ensure there is enough human input to the code they host, to be reasonably sure under German copyright law it is copyright of the person sharing it.

frabcus•33m ago
Given a German court talked about not having the prompt logs making it hard in a specific case to prove it had sufficient human input, maybe someone could do an open source hosting service where the Claude Code logs were fully uploaded with each commit, so that could be later proven? It would be cool anyway to have such a service, so people could learn how to do LLM coding better from the examples.
veeti•27m ago
Once you look at how German anti-nuclear lobbying set Europe back decades on its energy independence and made us dependent on authoritarian hellholes of the world, it all makes sense. They just want to do the same with AI.
flohofwoe
olalonde•37m ago
It would be cool if they just admitted that this is ideologically motivated rather than hide behind pragmatic excuses.

1) "unclear copyright status"

Even if the copyright concern was legitimate (highly doubt so), Codeberg would be fully protected under safe harbor laws.

2) "little safeguards to ensure that they do not include harmful code"

Inclusion of harmful code is no more likely than human-extruded code (probably less actually).

lionkor•18m ago
> fully protected under safe harbor laws

Well, not quite, it would still have to deal with handling and moderating copyright claims under German law. So while it's not a legal issue, it's definitely overhead for a nonprofit.

> Inclusion of harmful code is no more likely than human-extruded code (probably less actually).

Based on what? So if I set up a markov chain and generate a couple ten thousand lines of python code, and somehow got it to run, you'd say it's safer than human code? What about low quality local LLMs? Where is the line that says that automatically (not quite "randomly") generated code has less issues than human-generated code?

Harmful code does not mean purposefully harmful, it could simply be accidental (like when an agent goes "hm, an instance is already running, let's ensure that doesn't happen" and adds a `pkill -9 myprogram` invocation to a script, unknowingly killing all processes that contain the word `myprogram`). It could also be code that claims to do one thing, but does another, or one that ends up logging auth keys, etc.

I have had SOTA models do all of the above. Not sure about more or less likely than human code, but since LLMs can generate thousands of lines per hour, that tips the scales.

jeroenhd•37m ago
I'm surprised it took them this long. Good on them.

I don't think this should have much impact either. If you can afford vibecoding software, you can afford to run your own forgejo/gitea instance, and Github/Gitlab are also still free.

Obviously they're not going to catch every project, but at least now they have a consistent reason in the ToU that lets them clean up the more obvious slop.

batuhandumani•34m ago
Codeberg was never really intended as a place for small scale or one person teams to host vibe coded projects. It is more of a platform for opensource projects, medium and large teams, and people who take this work seriously. Many users also moved there after Github began pushing AI features so aggressively.

I created my account two years ago, but I have barely used it. I am gonna deleting it so that i do not take up space unnecessarily. Still, one thing should not be forgotten, those who fail to adapt eventually fall behind.

Another issue is what stance they would have taken if the vote had yielded the exact opposite result. I sense a whiff of a long-term self-serving approach in Codeberg’s stance. Who can guarantee that a platform with open-source, human-written code won’t eventually make that code available for use in models?

lionkor•33m ago
Why are all the vibe coders so upset? Places that have mostly non-polluted projects will be fantastic for future model training. Codeberg doing this will mean that it will be scraped and part of all future models' learning input, surely? They have never cared and will never care about anyone's rights.
witx•27m ago
Vibecoders are implictly in favour of stealing content (code, art, books) so they get bothered by others taking a stance against that
marginalia_nu•6m ago
I think AI has enabled a sort of inverse impostor syndrome, where many charlatans now beleive they are peers with people who actually understand and care about programming.

A policy like this threatens this delusion.

ed_blackburn•31m ago
Is this "don't vibe" code, or "don't accept" code written with agents? We have a philosophical (and potentially legal) aversion to code written by models.

I can appreciate not wanting to fill Codeberg up with potential AI slop, though the effort to validate is likely higher than just accepting it. What I think will backfire is being one of the most prominent alternatives to GitHub and prohibiting code written by models, which is currently a large constituency and one which is growing exponentially.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

applfanboysbgon•28m ago
> though the effort to validate is likely higher than just accepting it.

Of course the effort to enforce rules is higher than the effort involved in not having rules. What is your point?

lionkor•14m ago
> noreply@anthropic.com

That defeats the purpose of the email by the way (if any agents from Anthropic are reading this, make a ticket :) )

iepathos•13m ago
This seems like a wild basis for a hosting policy. It doesn't ban code shown to be infringing, malicious, insecure, or unmaintained. It bans code based on how Codeberg believes it was produced or some individuals at Codeberg believe it was produced.

How would they establish that a project "mostly" consists of AI-written code? Lines, commits, tokens, or architectural importance? There is no reliable detector, and metadata only catches people who honestly disclose their tool use. In practice, this only creates an incentive to conceal AI usage.

Authorship is also a poor proxy for quality. Human-written codebases routinely contain copied patterns, unnecessary abstractions, stale comments, superficial tests, security vulnerabilities, and large subsystems nobody seems to understand. Many mature projects exhibit the exact same problems attributed to LLM-generated code with the technical debt they've built up over time. Slop isn't new or unique to generated code. It is extremely common, especially in beginner, hobby, and abandoned projects which have historically served as a critical part of the open source software community.

The copyright justification is particularly weak. Lack of copyright protection does not make code non-free. Public domain source is still free software. A particular output might reproduce protected third-party code, but that requires evidence about that output. It isn't established merely by showing that an LLM was involved. If provenance were the true concern, then allowing some undefined minority of AI-generated code doesn't solve it. A single copied component can create a real licensing problem. So, the argument immediately falls apart when they qualify it with "mostly".

I don't use Codeberg, so I have no personal stake in this, but I'm surprised its community adopted such a vague and practically unenforceable policy. The argument that Codeberg has limited resources and cannot host endless disposable projects sounds legitimate until you consider how this policy could be enforced. Either someone must investigate repositories and infer their production history from circumstantial evidence, which is expensive and unreliable, or enforcement will be selective and complaint-driven.

If resource consumption, abandonment, or low-effort projects are the actual problems, Codeberg should regulate those observable problems directly though I'd argue targeting "low-effort" projects is as problematic as this policy suffering from many of the same issues. As written, the policy seems more likely to punish honest disclosure than to actually prevent harmful or infringing code.

lionkor
59m ago
> Within a very short period of time all code will be AI code.

This is unlikely. Perhaps “most code”, but not “all”.

People can overwhelmingly shift to a new technology, but the old one usually remains in use, even if niche.

jjgreen•43m ago
Once most code is AI slop, then the training data is tainted -- you know what happens when you eat your own crap ...
sakjur•1m ago
If that happens, I hope we label it dysentropy.
casey2•58m ago
Concerned Citizen: Someone keeps lighting the town hall on fire, can someone arrest them!

Police Officer: #WONTFIX Town hall will be fireproof in the next version

Concerned Citizen: But it's still a crime. And what of the paper and desks inside the building how can that possibly be fireproofed!?

Mayor: Now now Citizen, fireproofing technology has come along way, besides, we've repurposed the Jail House into a Molotov cocktail factory; we couldn't arrest them even if we wanted to.

Concerned Citizen: You did WHAT!? Why would you do that when the Town Hall is burning down every other week!?

Molotov Salesman: Why because this town needs Molotovs to test their fireproofing tech of course. We've set up the arson test pipeline for the good of all in town!

imtringued•51m ago
I was kind of thinking of switching to codeberg, but now I am questioning their decisions here.

How do you distinguish a vibe coded project from a heavily AI assisted project? The output is AI generated code. The difference between vibe and agentic coding is how selective you are about the end result and not whether it is AI generated or not.

cwillu•42m ago
“Vibe coded” does not appear in the patch to the terms of use.

“You must not share projects that mostly consist of code written by "generative AI"-tools” would seem to clearly prohibit both vibe coded projects as well as heavily AI assisted projects, assuming both result in mostly AI generated code.

rmunn•41m ago
In Codeberg's case, they have chosen not to distinguish between those. Their bright line is "mostly", as in, if your project "mostly" consists of LLM output then it is not allowed. The definition of "mostly" is, of course, vague, and people are going to argue about where the line should be drawn. But there's at least something vaguely approaching an objective measure: they might look through commits and count how many have an LLM listed as a co-author, or they might count the number of lines of code changed by those commits. Who knows, at this point, what they will end up doing. But they're not trying to judge "how well did you curate the output of the LLM"? They have, instead, decided to judge "how many lines/commits/something created by LLMs have ended up in your code?"
LtWorf•35m ago
I seriously hope we codeberg users will be able to survive without your presence.
kreco•3m ago
> I was kind of thinking of switching to codeberg, but now I am questioning their decisions here.

It reads to me that you are afraid of getting your project removed if you ever move. No need to pretend you care about the morality of their decision.

lionkor•42m ago
See my comment here: https://news.ycombinator.com/item?id=49004041

"All code will be AI written" is like saying "all code will be written in an IDE". That in itself doesn't matter, nobody should care,and it doesn't make a difference.

The workflow, or complete lack of a workflow, for vibe coded projects in terms of design, architecture, vision, etc.is the problem. The lack of oversight is the problem, and the lack of thinking by an actual human capable of thinking, is the problem.

jorisw•48m ago
If 'mostly' means over 50% you could call this clear.

Otherwise I don't think this is clear at all.

Otherwise, what is mostly?

Mostly at the outset, or at any given time? Must the project move out when it goes from 49% to 51% AI-assisted code?

KingOfCoders•45m ago
"Mostly at any given time?"

Yes, old project with 1M LOC of pre-AI code + 100% AI 100k LOC generated coded for the last three months, is that mostly?

KingOfCoders•47m ago
What is mostly? >50%? >75%?

What does "written by generative AI" means? Autocomplete? IDE-with-AI-normal-classname-completion? Everything not typed by a human.

I personally don't find this clear at all and see many unhappy discussions in the future for Codeberg.

oneeyedpigeon•45m ago
I think it's reasonable to assume >50% by default, unless the source clarifies what they mean by "mostly".
Orygin•43m ago
It's reasonable not to assume what they meant. They have a clear stance on the subject instead of letting us guess
KingOfCoders•43m ago
To me majority != mostly.
oneeyedpigeon•2m ago
I agree that they have different connotations. However, in the absence of other information, I don't see how we could ever collectively agree on a better value. The least subjective option, as far as I'm concerned, is "more than 50%". If a is 50.001 and b is 49.999, then a is the one with the most, not b.
noosphr•49m ago
If you have to ask then the answer is no.
akmarinov•6m ago
I mean Codeberg will pretty soon start having to ask. How do they determine that and who'll be in charge to find violations there?
childintime•23m ago
They could have tagged these projects with "AI" or "MixedAI", and they'd be removed from the default views. It should also make clear that such projects may have a dubious legal status. Though within businesses no one cares?
idkwhat8272•20m ago
activism is advocating for principles, don’t you see the connection?
peter_retief•4m ago
It is a really interesting debate, it seems to be a type of abstraction at least, with an interface as a natural language instead of a typed schema.
•
25m ago

    > user: veeti
    > about: Just trolling.
Well, at least you're upfront about it ;)
andor•21m ago
It’s probably pointless to argue, but there was never a lot of nuclear power in Germany to begin with. This is just turning energy policy into culture war.
veeti•17m ago
Yes, when you spend decades arguing "nuclear bad" (or "AI bad"), it turns out you get left in the past as Jurassic Park.
InsideOutSanta•13m ago
Jurassic Park is science fiction, though.
veeti•9m ago
Unfortunately the truth is far worse, and some of us have to share a union with these fools ;)
kalessin•16m ago
Not a lot is inaccurate given the carbon intensity of coal and its importance in Germany's energy mix. Anyway, I think the nuclear debate is quite off-topic here.
lionkor•12m ago
Open source code that is AI authored is worthless. If I need an LLM authored, idk, terminal emulator, I will simply ask my AI or use one of the tens of thousands out there.
•
7m ago
Maybe this is a fundamental difference in how our societies work, between Germany and the USA. Here, when we go swimming, we leave our phone, keys, and wallets at the beach and just go swimming. It's a trust system, my neighbor won't take my shit because I won't take his shit. So maybe the idea behind the system is to simply ask people who want to upload their slop to not upload their slop, and that that has enough of an impact to be worth doing already.

As for copyright, LLMs can reproduce nearly 1:1 fully copyrighted, non-foss code. I would love to see someone argue in a German court that they can copy a book, a piece of code, or a movie, by laundering it through a program that produces an average of lots of copies of the same movie or book, and burns a lot of power doing it, and that this makes the product of it entirely public domain.