How could we know whether incoming code is AI generated or not? are there tools for this?
"If I don't know you, I don't merge you"
And if you catch somebody submitting code they can't explain, you don't know them anymore.
It's really simple. Open source has always had a social layer. Github culture tries to eliminate it, and that's the source of this vulnerability.
First thought I had too. I deliberately strip AI metadata from my PRs in certain orgs.
"If I don't know you, I don't merge you"
And if you catch somebody submitting code they can't explain, you don't know them anymore.
It's really simple. Open source has always had a social layer. Github culture tries to eliminate it, and that's the source of this vulnerability.