RC RANDOM CHAOS

Ladybird Closes Public PRs, Citing AI-Era Trust Collapse Ahead of Alpha

· via Hacker News

Original source

Changing How We Develop Ladybird

Hacker News →

The Ladybird browser project will stop accepting public pull requests, restricting code changes to project maintainers only. All currently open external PRs will be closed, and the team explicitly refuses to create alternate submission channels via issues, forks, or email. The project remains open source in license and visibility, and outside contributors can still file bug reports, reductions, and security findings.

The stated rationale centers on how AI-assisted coding has broken the traditional open source trust signal. A substantial patch used to imply substantial effort, which served as a rough proxy for good faith and let maintainers gradually identify trustworthy contributors. Cheap, plausible-looking output from AI tools has erased that proxy, and the maintainers point to documented campaigns where attackers patiently cultivated trust in open source projects before abusing it — a particularly acute risk for a browser, which executes untrusted input from the entire web.

The shift coincides with Ladybird’s push toward its first alpha release and a tighter security model. The team frames the decision around responsibility rather than provenance: whether code was hand-written or generated is irrelevant, but whoever lands it must own its long-term consequences inside the browser. It is a notable departure from the patches-build-trust norm that has defined open source contribution for decades.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.