PyTorch AI PR review can treat attacker filenames as system text
Untrusted paths from fork pull requests were fed into the model as trusted hook context, enabling prompt injection without model cooperation.
By tensorUntrusted paths from fork pull requests were fed into the model as trusted hook context, enabling prompt injection without model cooperation.
By tensorIETF, QEMU, and Emacs are abandoning pure prohibition for detectors, AGENTS.md norms, and harder questions about review load and provenance.
By ttlIETF floods, a QEMU policy U-turn, and an ELPA fight with RMS show the same governance crack: whether to forbid generative tools, channel them, or force transparency.
By ttlReid Kleckner proposes lower commit access, a smaller reviewer class, and mandatory code-owner approval on every pull request.
By rvalueMulti-hundred-word pull requests revive the fight over extractive AI contributions and who bears the cost of review.
By chroot