this post was submitted on 31 Oct 2025
1033 points (98.8% liked)

Programmer Humor

27193 readers
1028 users here now

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Magnum@lemmy.dbzer0.com 20 points 4 days ago (2 children)

The usage of vibe coding tools in the NPM repo has only led to two major incidents (supply chain attacks) in the last months

[–] dogs0n@sh.itjust.works 4 points 4 days ago

Oh interesting, I thought they were all phishing attacks.. goes to show the risk I guess.

[–] Valorie12@lemmy.world 4 points 4 days ago (2 children)

Tbf this is why PRs and code reviews exist.

[–] dogs0n@sh.itjust.works 9 points 4 days ago (1 children)

Agree, but if we are going towards the AI writes all code future that these AI companies want, then code review will become inneffective.

If we stop writing code, we will lose that "edge" that helps us detect bad logic when reading a PR.

The more code we have to review, the more mistakes we will make letting bad code through (I believe this is the case). It's less fatal when the code we review is written by smart humans because it's unlikely they code something as bad as an AI can produce.

Anyways, I think using any AI agent to write bigish blobs of code is a mistake, but if you are gonna do it i hope you have multiple fresh pairs of eyes on each PR. Still will give me the ick seeing an AI PR get merged tho.

[–] Valorie12@lemmy.world 1 points 3 days ago

Fair, I can agree with that.

[–] Magnum@lemmy.dbzer0.com 6 points 4 days ago (1 children)

I think it was reviewed and comitted by AI or something

[–] Valorie12@lemmy.world 1 points 3 days ago

That shouldn't count IMO