Changes to SourceHut's terms of service regarding LLMs
160 points by seb
160 points by seb
I respect SourceHut and Codeberg for standing up for what they believe in, but I can't help but feel they're resigning themselves to be niche services for hobbyists (even more so than they are now). Maybe that's exactly what they want, but it's sad to me that two of the most notable GitHub alternatives are now off limits to the majority of modern software development.
I believe there is a place for LLM-authored projects in open source, and that the world would benefit from having an open, non-proprietary place that accepts and nurtures them.
I think you're stuck between the devil and the deep blue sea, my friend.
The devil is that if LLM use helps you a lot, it's probably because it's doing something immoral or outright illegal, like ripping the license off OSS code.
The deep blue sea is that if you're not doing anything immoral, you're still likely killing yourself and your project by ceasing to learn, ceasing to build tools, ceasing to feel pain, and above all ceasing to build community.
and above all ceasing to build community.
This sentiment really hit me just now because it puts into words a feeling I've been having recently with all the vibe slop at work. Instead of working together, people just go into their bubble with their Cursor or Claude and post it verbatim at you in Slack and PRs. It's stopped feeling like I'm working with real thinking, feeling humans, and that they don't see me as a human on the receiving end of this.
So much this. It used to be, if I saw some code I didn’t like, I could have a word with the author, and one or both of us would come away with a better understanding of how to approach the problem (maybe I was wrong and there was a good reason!).
Now that conversation stands and ends with “shrug, that’s what the LLM went with”
Anyone giving such a lazy answer really needs to learn some manners and self respect
To be fair, most of the time I don’t even bother starting the conversation, because what would there be for them to say?
and above all ceasing to build community.
This sentiment really hit me just now because it puts into words a feeling I've been having recently with all the vibe slop at work.
I think this aspect deserves much more attention than it receives currently, and it is not at all restricted to work. How are open-source communities formed? It all starts with a problem someone has. The pre-LLM way for you to approach this then was either of 1) look on the Internet whether someone has solved the problem with an open-source library, or 2) write it yourself. Because 2) was a lot of work until LLMs, 2) was only taken if 1) failed entirely or very individual reasons made pre-existing solutions unfitting (e.g. incompatible license). In all cases of 2) a new project was born, which might become the next person's option 1). Once option 1) however was chosen, you dealt with a foreigner's project – if you had problems with it, you asked for support, or you ideally contributed a patch. Over time, a relationship between you and the project was established, maybe you helped other people, maybe your patches get accepted more quickly or you might even be promoted to a co-maintainer. The more people chose option 1), the more the project's community grew.
Now, LLMs have made option 2) so much cheaper than option 1) that it seems likely that the building of new open-source communities is going to cease entirely. Instead of using an existing project and participating, people are going to ask Claude to write something anew from scratch. Even if a foreign project still is used for some reason (like, e.g., a good security record, because, maybe you do not want Claude to write your crypto library and prefer to use something like OpenSSL), instead of asking for support and participating in a community, people are going to ask Claude. And instead of contributing patches for maybe-not-so-unusual use cases for an existing project upstream, people are going to ask Claude to do it locally for them.
I think this is the end of programmer communities.
I think this is the end of programmer communities.
Well, it's the end of communities of programmers who haven't banned LLMs; sure.
I'm beta testing a mostly LLM-authored project right now. I had a bunch of bug reports and feature/polish requests (some for edge cases) that the maintainer fixed within minutes. Previously they would have likely gone onto a backlog. I think software communities are going to be differently shaped, but the very rapid iteration here is meaningfully better than the before times.
In general, the solution to people using high-quality dependencies over vibing their own (which I agree is generally not great) is to make it as easy as possible to surface and use those dependencies. For instance, every language community needs to have a great package manager which acts as a Schelling point for how to fetch code. LLMs definitely put pressure on tooling to do better at that, but I consider that kind of competition to be a good thing.
I'm beta testing a mostly LLM-authored project right now. I had a bunch of bug reports and feature/polish requests (some for edge cases) that the maintainer fixed within minutes. Previously they would have likely gone onto a backlog. I think software communities are going to be differently shaped, but the very rapid iteration here is meaningfully better than the before times.
LLMs generate entropy, quickly. Rapidly iterating with an entropy exponent is not the killer feature that it appears at first to be.
We shall see whether LLMs can improve faster than they compound their entropy. I am not betting on either side of this one; they're amazing tools, but they're not very good at building readable, maintainable software (yet). OTOH, if you assume that the LLM is going to fix what the LLM has shat out, then the readability and maintainability don't matter. Like I said, I can't bet against LLMs, but I'm not stupid enough to bet on them, either.
Right, that's the big risk. They are very good at making a codebase much worse very quickly. But also the ability to try things out with less regard for long-term maintenance is also valuable.
the solution to people using high-quality dependencies over vibing their own (which I agree is generally not great) is to make it as easy as possible to surface and use those dependencies
Then again, we've slowly been realising, over the past years, that the dependency tree explosion that languages with frictionless package managers have enabled is not always good either. (What with supply chain attacks and all.) Making it as easy as possible to pull in dependencies might win over the person who would vibe their own version otherwise, but is that really the person that you need to win over?
I don't contest that better tooling is good, though.
Then again, we've slowly been realising, over the past years, that the dependency tree explosion that languages with frictionless package managers have enabled is not always good either. (What with supply chain attacks and all.)
Well, people vibing their dependencies is somewhat more resilient to dependency compromises! I would much rather us focus on making public registries safe from bad code, such as via dependency cooldowns, which give automated security scanners a chance to hammer at them for a few days before ordinary users see them.
I realize this is a somewhat accelerationist viewpoint -- those automated security scanners are going to be using LLMs these days for part of their work, so in a sense it's using LLMs to solve problems that LLMs have created (or at least heightened the contradictions of). But I don't see another feasible way out.
I do not want my code forge to make moral decisions on my behalf.
Is there a code forge that doesn’t make moral decisions on your behalf, or are you choosing to ignore the ones that are normally glossed over for commercial convenience like “genocide and ethnic cleansing are fine as long as the check clears” and “LLMs may cause widespread devastation environmentally, emotionally, and socially but but they also help a lot of people get to work on time, so, it;s impossible to say if its bad or not,”
Are you a sourcehut customer?
I was a paying customer for years until a few months ago. I still have a number of projects that predate LLMs on Sourcehut, but they're in maintenance mode. I cancelled previously because of Drew's frankly obnoxious political grandstanding and the continued bleed of that into Sourcehut (both community and policy-wise)
I see. They consulted customers before moving forward with the policy, but if you left a few months ago, I don't think you'd have seen it.
That said, as a paying customer who followed the discussion closely, it didn't feel like they were making a moral decision on my behalf; they were taking a moral stand on their own behalf after a conversation with their customers, and have now announced an implementation of that stand with plenty of transition time/cushion for people who don't consider that stand compatible with their own.
Based on your lobste.rs profile, I see you currently use github. They've made a moral decision (to maximize promotion of and use of LLMs) on your behalf. Do you object to that one, too?
I did follow the discussion because I still host projects on Sourcehut and am subscribed to some of the mailing lists.
it didn't feel like they were making a moral decision on my behalf; they were taking a moral stand on their own behalf after a conversation with their customers
They are forcing those who use their platform to conform to their moral viewpoint or leave. It's their right to do that, but that doesn't mean they aren't making that decision for their users. If it was strictly a technical or legal issue, they would not apply the policy as a blanket, they would target abusers and public projects only.
Based on your lobste.rs profile, I see you currently use github. They've made a moral decision (to maximize promotion of and use of LLMs) on your behalf. Do you object to that one, too?
They are not forcing me to use LLMs, advertise them, or really do anything other than offering me the option. They are giving me the decision to use them, not making one for me. That is very different from what Sourcehut is doing.
FWIW I like Sourcehut because Drew has excellent technical judgement/tastes, I leave primarily because of the non-technical aspects that are primarily dictating the project (and Drew's blog) these days.
They are not forcing me to use LLMs, advertise them, or really do anything other than offering me the option.
They surely have:
https://github.com/orgs/community/discussions/194075
I'm not sure whether they're currently doing that, but I expect it to return.
That is only if you actually use copilot, which I don't and probably never will.
It read to me like people were reporting that happening just because they used VS code in conjunction with github tooling, even without copilot.
Also, FWIW, I don't view this as a non-technical decision. The blog post here mentioned several technical reasons they don't want this on their service, in addition to all of the moral reasons they want to keep it away.
It read to me like people were reporting that happening just because they used VS code in conjunction with github tooling, even without copilot.
Then it sounds like a bug and appears to have been treated like one.
The blog post here mentioned several technical reasons they don't want this on their service, in addition to all of the moral reasons they want to keep it away.
They themselves say it is primarily a moral decision on their part:
But, in truth, the rationale is more about politics and ethics than anything else.
If it was purely a technical issue they would instead ban abusers as needed, which they're going to have to do anyway.
Yes, but it's a moral decision on their behalf. As evidenced by the statements about how projects that don't use LLMs to generate artifacts that hit their service are not banned, even though they discourage all LLM usage. Not a moral decision on my behalf.
Sure, but that's in a vacuum. Any human can only take so much real-world abuse before something snaps and you say "no more"
Personally, the reason I'm moving away GitHub is that it's a centralized platform controlled by corporations, with deteriorating UX. But, it does also seem to me that LLMs are also doing the same thing to the whole world, so I really can't help finding "open, non-proprietary GitHub alternative for LLM-authored projects" quite ironic...
there's this one that's LLM friendly https://codefloe.com/
Codefloe is quite nice - always up, fast, stable, and development of new features is proceeding quickly. Crow CI (which they host but you can run locally) is also great, been using it for my homelab for awhile.
Meanwhile, I can't help but feel that GitHub is resigning itself to be a niche service for slop. Gets harder and harder every day to take anything hosted there seriously.
Yes, LLMs have made it much harder to asses software quality. I expect "project is hosted on a no-LLM forge" to become a useful heuristic, that may play in those forges's favor.
There's also CodeFloe, a Forgejo-based forge with CI and static site hosting built in. When Codeberg announced its anti-AI ToU update, CodeFloe posted that it welcomes people moving their repositories off Codeberg while staying on a Forgejo instance. It's donation-funded and aiming for cost parity rather than run as a commercial product, so the incentives look a bit different from GitHub.
Whether it ends up as the open home for LLM-authored projects, I don't know. But it exists, and it's one option for people caught by these policy changes.
Both Codeberg's and SourceHut's source is free software. Noone is stopping anyone to set up an alternative forge that is friendlier to the things these two banned.
There's GitLab and Tangled too, both fine with LLM stuff, if I remember correctly.
You should give Tangled a try.
I really enjoyed Tangle a lot. I think you guys are diving into a good amount of innovative solutions, which is largely what I want out of a new platform. That being said, I really hesitate to use it without being able to have private repositories in some place. Mostly due to me not wanting to manage two separate places for my repositories.
Luckily there are many forges, hosted and self-hostable, available for generated code. I'll be interested to see how many people managing FOSS repos choose Codeberg and SourceHut in order to avoid endless waves of crappy generated pull requests and tickets. Dealing with crappy hand-made PRs and tickets is already a lot to handle without automating it. 😹
I gambled on moving to GitLab a couple years ago for different reasons and have since wondered if I should move to sourcehut or codeberg instead to support FOSS... seems like that question resolved itself.
I don't think that writing good "tasteful" code with good practices is necessarily mutually exclusive to using LLMs, but I do understand to some extent why the blanket policy exists. People are likely to abuse underspecification of AI restrictions in the ToS.
Exactly my thoughts. Not to mention the exclusion of the Linux kernel to avoid losing big open source names, makes the entire thing a bit “controversial”. Little Joe needs to learn ASM to write three lines of code and prove he did so, but corporation X can write a Linux driver using DeepSeek, no problem. lol.
I don't think I know any programmers who don't use LLMs to assist writing code. Even among those who don't vibecode, don't use local agents, type all their own code into their own text editor, it's still an integral part of a modern programing workflow. This policy basically makes sourcehut unusable for serious software projects.
This is a statement about what you know rather than a statement about programmers generally. I know plenty who do not use LLMs in any capacity.
I estimated in another comment that I think that at least 90% of working programmers are using LLMs to some extent as part of their work. Do you think that is a drastically wrong estimate?
I think it's...simply incorrect to try to generalize from the small, non-general sample you know to the total programmer population? Like, there isn't really a way to do that "correctly" in the first place.
Slashdata's 2026 state of developer adoption does seem to give that kind of numbers (page 28). Caveats are that, like many others, Slashdata has heavily increased it AI reporting (which can introduce biases), and that they only report professional use (the usage patterns for personal and FOSS projects seem very different). FWIW, StackOverflow also had comparable (but lower) numbers in 2025, interestingly with "use" and "sentiment" trending in opposite directions.
Slashdata has heavily increased it AI reporting
I think that's quite an understatement. They literally brand themselves as an AI development researcher now.
The professional vs personal use bit is probably important, yeah, because use that's mandated and use that you choose willingly might be different. I can't view the slashdata page w/o some sort of sign-in wall, but at least in the SO data they don't seem to explicitly measure whether people were required/pushed to use it.
I won't comment on its accuracy, but i think it's a very misleading measurement, like when a game reports total number of downloads as a "number of users" metric.
There are, for example, a great many professional devs who are required to use LLMs in their work whether they want to or not. That would drive up the measurement, but not what the measurement wants to represent (acceptance or proactive use of the tools). I know personally multiple devs who are not in the "required to" camp, but are in the "expected to and fearing for their jobs if they don't", which will do the same.
Doesn't matter if the measurement is 90% or 40%, if you're measuring "use by professionals", you're not measuring "people who want it".
I've heard "I need to use AI are work, it's making our product worse and I absolutely hate it and it's completely draining my will to live" and similar more often than "I use AI and I'm lovin' it".
I don't think it's so cut and dry, but I think it's also easy to fall into a feedback loop that could make it feel like it is that cut and dry.
I enjoy working with LLMs, when I choose to do so. I would feel very differently about them if I were forced to use them, and in haste.
Also, the "% of LLM-using devs" stat doesn't say anything about how important LLMs are in their workflow. Using LLMs for a small fix or refactoring here and there isn't the same thing as using it to generate important features or making design decisions. Full LLM converts might decide they don't want to contribute to a no-LLM project, but most devs will make more nuanced decisions.
I have no idea how any of us could make any estimates about the habits of all programmers. That data seems extremely challenging to collect with any accuracy.
You now know at least one. Hello. :) I have opened ChatGPT once (to verify that some content of mine was ingested improperly) and that's about it.
Integral? How?
I don't use LLMs when working on ClojureScript at all per Clojure policy. After some extensive experiments last year with Opus, I decided to give up on generative assistance on personal projects - mailing lists, irc and patience if I can't figure it out myself from docs or searching the web.
I moved my personal projects to SourceHut because it is one of the few options that takes a fairly principled stance against the general decline of commercial software - SourceHut loads just as fast for me on a ten year old computer running NetBSD (also anti-LLM and serious) as it does on a M4 laptop running MacOS.
This policy change around LLMs seems very on-brand.
The author of the piece you just read is the main developer and maintainer of sourcehut. It is certainly a serious software project by any measure I can come up with, and they use it to maintain sourcehut itself.
Coupled with the replies in this thread, it would seem that you now know multiple programmers who don't use LLMs to assist writing code. And you now know of at least one serious project for which sourcehut is very usable.
Fennel is another serious software project that doesn't use LLMs and finds sourcehut very suitable.
It's not hard to find more if you're interested.
The development guidelines of Offpunk state:
"Output of chatbots are not welcome in any form. Every contribution/question/message should be written by an human who takes full responsibility about it."
I don't think you can logically get to that objective conclusion (and a hyperbolic one, at that) from that subjective observation.
I don't think I know any programmers who don't use LLMs to assist writing code.
For work: Yes, we're required^W strongly encouraged to use LLMs and soon won't have a choice.
Personal projects: No.
Nice. So "If you don't use it, you will be left behind" phase is followed by "Everyone is using it already". I wonder what comes after.
At my work we contractually cannot use LLMs with our largest (public sector) client. The only assistance I'm allowed is Google's AI Overview since I can't seem to turn the damn thing off.
Moreover, the use of AI for purposes other than co-authoring code, tickets, emails, and so on, is discouraged but not prohibited. If you use LLMs privately to review your work, to ask questions of, to perform security analysis, and so on, and then write original code to push to SourceHut, your use-case is aligned with our policy.
Seems like they agree there.
Frankly, overall I do think this is a well written document with a lot of nuances and important but sometimes subtle context.
In my reading of the policy using an LLM for a simple task like finding the correct API call for a given purpose would be against the terms of service. I appreciate that not every developer does this, but my guess (and I accept this is a guess, but I have high confidence in it) is that the proportion of working devs who don't work in this way is now under 10%.
Where do you read that?
If you use LLMs privately to review your work, to ask questions of, to perform security analysis, and so on, and then write original code to push to SourceHut, your use-case is aligned with our policy.
"Finding the correct API call for a given purpose" seems to fit very directly under "to ask questions" as long as you don't then have the LLM write the code for you.
If the AI gives me code that I choose to type into my source file, even if it is just a single method invocation, surely that is "the use of LLMs or other generative AI tools to produce or assist with the production of source code".
Maybe just accept that Sourcehut is not for you and move on?
Sure, fair enough. Of course it's their right to run their service how they like. But I think that from the perspective of the lobste.rs community of open source developers, it's worth discussing that this likely makes it unusable for the majority of people who might otherwise want to use it. Moreover, I think highlighting the existence of counterexamples, which naturally always exist, does not alter this fact.
Sourcehut is a niche product. Them saying "we don't accept LLM content" is not a marketing bug, it's a marketing feature.
I think you'll want to nuance "unusable" here, because I found their post very reasonable.
The fact is (very likely) true, I mean sourcehut/codeberg/tangled aren't going to get the network effect pressure like github soon-ish. But that's...also not always the goal for OSS devs.
An comparison that comes to mind is, just because Java is one of the most used languages, that doesn't mean I can be productive in Elixir/Gleam/Rust/Zig etc. You won't have the ecosystem, but you can still deliver a technically valuable product, the rest is most likely social.
sourcehut/codeberg/tangled
Don't throw tangled into the same bucket as the other two. Tangled does not close itself to LLM code.
Correct, we don't have any policy regarding LLM code. Self-hosters are free to decide and enforce this as they please.
In that sentence I wanted to point out their impact on network effects compared to GitHub, and that most people wouldn't hop over anytime soon anway, still they are usable because their focus is different, people are drawn to the forges choices.
Codeberg as far as I understood it, didn't close itself in a very rigid way off LLM code? Maybe next vote changes things, I dunno.
Codeberg as far as I understood it, didn't close itself in a very rigid way off LLM code
From the policy you cannot really derive a clear boundary, my interpretation is that it's not the place to host any LLM generated code.
I agree there is not a clear boundary! I ended interpreting it differently than you.
I can understand your point of them being closed off.
Not really related, but in the case of tangled, hosting your own tangled with your own policy is going to be interesting, or just keeping all your repos vouch based(we can use LLMs you cannot).
I still dunno about how any those will hold, but I do have a strong feeling that GitHub isn't to be irrelevant anytime soon.
If you're shoveling code from the AI into your source file, manually or otherwise, that's different. You asked about finding the correct API, not that.
I think the intent and the mechanics of this policy are clearer than any I've read. Maybe sourcehut is not for you, but there are clearly other programmers working on serious projects who find it workable and even pleasant.
They might have a different emotional valence, but when it comes to this policy there is zero difference between 'shoveling' code and 'carefully and mindfully retyping' code.
And both are materially different than how I understood your statement. You said:
finding the correct API call for a given purpose would be against the terms of service
I understood that to be something like asking ChatGPT: "How do I use libfoo to frobulate an array of bar_instances?"
An appropriate response to that would be "Call frobulate_bars(bar_instance *). Here's an example..."
and you'd still need to look at the example and write the code that fits in your project. That is very clearly within the scope of what they say is OK.
Asking it to generate code and copying it, whether with a shovel or with manual typing is clearly different.
There's quite a jump from "find the correct API" to "give me code to type in".
Well not really. If my question is "What is the correct interface to convert from PNG to JPG in libpicasso", and the answer is picasso.fmt_convert(my_img, picasso.fmt.PNG, picasso.fmt.JPG) then there's no jump at all.
Right, but if the answer is that simple then it would have been much easier to just check https://docs.rs.
I just tried that and failed at the first hurdle: https://docs.rs/releases/search?query=Libpicasso
Second attempt got me to https://docs.rs/crate/picasso/latest which helpfully says "Picasso is not a library".
Right, I assumed "libpicasso" here was an arbitrary example, not an actual library. Unless they're talking about the toy C# library from over a decade ago?
(And in that case… Microslop has had decades to get their docs situation in order. That they still haven't even bothered to try should say plenty.)
Hah! Yeah, my bad, I didn't think to check if Picasso was made up or not.
(I wonder if an LLM would hallucinate an answer and lead me further astray...)
Yes, LLMs have made it much harder to asses software quality. I expect "project is hosted on a no-LLM forge" to become a useful heuristic, that may play in those forges's favor.
That's not a reasonable interpretation of the policy, as written. In any case, these things aren't put in place to micromanage every individual's personal development, it's so they have clear grounds to deal with projects that are causing problems. If you like sourcehut and you happen to use LLMs responsibly and in a way that is essentially invisible and won't create problems for the community and platform, a reasonably policy like this is not going to be used to witch hunt you off the platform.
The policy says,
We intend to use a light touch with enforcement.
But, if you're creating ream of projects with buggy slop and stressing the CI, they have grounds to address it.
I mean, "to ask questions" is right in there. So if it is purely asking what call might be used and you then implement that yourself that seems okay. If you however ask it to write the api call in question and use that code directly it does cross the line the are drawing.
Which is a bit more restrictive than a lot of devs are doing these days, but also not unheard of. And, I think is still the best way to actually prevent personal skill atrophy. Something I have commented on before.
integral part of a modern programing workflow
From the developers I know, usage seems to vary quite wildly, especially depending on if people think their jobs depend on it.
I've been purposely trying to rely on them on purpose to "move fast like everyone else is doing", but I can't keep it from noticeably slowing me down. It's faster for me to google than wait for a LLM response, or use grep or septum to find what I'm looking for. If I generate, it takes longer to understand what got made from the CLI and then to correct it.
It's reminiscent of how everyone in the 90s started "multitasking" and then thirty years later there's podcast on how to focus on one thing.
It's faster for me to google than wait for a LLM response
Google is actively trying to change this, by making their regular search results worse and worse, it seems. I know people who basically use LLMs as "less-broken google".
I know people who basically use LLMs as "less-broken google".
I have been guilty of this (I use DDG, but the point stands). A lot of the internet is just hopelessly unusable for finding answers to generic questions on a mobile device because of all of the ads making sites unusable. I could probably figure out a way to fight the ads on my iPhone (there are more options on Android), but if I want the answer to something stupid like "is Tehuacan Brillante water owned by a large international company similar to Topo Chico", I'll get it a lot more easily and quickly with Claude than with an internet search.
And I feel a pang of guilt (bad for the environment) and rage (Google themselves played a part in making the SEO optimized ad monetized internet like this, and now they're foisting AI upon us that was build with stolen ad-ridden content). But I do it anyway because I'm weak and love convenience I guess. :(
This policy basically makes sourcehut unusable for serious software projects.
I pretty frequently see sentiment like this, and I always wonder how people manage not to consider that maybe sourcehut or codeberg don't want "serious software projects" to use them?
Nope, what they don't want is projects using LLMs. They rationale is pretty thoroughly stated, why reinterpret ?
The dissonance here comes the parent implying that all "serious" projects use LLM, which is at best a big observation bias and at worst an insult to the alleged "non-serious" projects. The term "serious" is way too fuzzy here.
I don't! The closest I've come has been reviewing a couple of fully vibecoded projects for my employer. I may be forced to eventually by management, but I honestly hope not. I do expect to need to use LLM-based tools for security review, in the same line as a fuzzing tool, and I hope to be able to use a local model, but no guarantee.
As a counter annecdote, the majority of the programmers I know personally don't use LLMs in any capacity.
I am not a their customer, but my personal interpretation is that assistance in writing code is not the same as LLMs co-authoring code, which their policy does explicitly forbid:
Moreover, the use of AI for purposes other than co-authoring code, tickets, emails, and so on, is discouraged but not prohibited. If you use LLMs privately to review your work, to ask questions of, to perform security analysis, and so on, and then write original code to push to SourceHut, your use-case is aligned with our policy.
Although I’ve been trying to minimize my use of LLMs, I do use them but I don’t use any code completion features, and I never copy-paste snippets into the final code. I didn’t do it during the Stack Overflow era and there is little reason to start doing it now.
Simply Googling something, or DuckDucking it, might present LLM output towards me. Does skimming that make me an LLM user?
Technically yes, I guess. But, then again, I dont really fell like a user, more like a bystander.
I dont really fell like a user, more like a bystander.
Maybe victim is the better word for this.
I moved to sr.ht to get away from Github as it began to degrade in the earlier days of Microsoft ownership and couldn't be happier.
Without really having a definite opinion about LLMs at large, I think it's nice to have spaces where their presence is less felt.
For what it's worth, I think federation solves this policy issue. We (Tangled) don't explicitly have an anti-LLM policy—you're free to host your code with us regardless of how it's written. That said, self-hosters can enforce their own rules at the "knot" level. Win-win.
I somewhat agree with this and also think that this means that projects like Sourcehut and Codeberg shoulnd't exist and selfhosting with your own policy means way more.
I have been a paid member of SourceHut for half a decade and I think I am done. I haven't used it much but have romanticized the thought of simplier services. Services that concentrated on the hosting and paying for that than one that was wrapped up in the noise around it.
I feel like this is the right move for Sourcehut, but I also feel like it's just another nail in centralized hosting.
Completely agree, and same. I have been a paying Sourcehut member for ~5 years, have really enjoyed it, and found it very useful. I think they're making the right decision here.
But, because I respect their position and don't think I can truly commit to not putting anything AI assisted on the site, I think I'm going to leave. Again, I think they're making the right call, but I mostly use Sourcehut for private hosting of little scripts I write for my use and my use only, and sometimes I use on-device models to speed that up. I can't promise that I won't upload any of that, and that's fine.
This is the broadest and most problematic such policy I have seen. It's especially surprising coming from a paid service. The free codeberg service has a much more reasonable policy.
I was always a sourcehut supporter because it seemed like it had a good vision, but it does seem in general to have stalled. That's not related to this policy of course but overall it's unfortunate.
SourceHut's simple, responsive UI is one of my favorites in all of software. I'm staying and paying, though I'll have to migrate one repo out.
Interesting wording.
original content written with or which facilitates the use of LLMs
So that would allow refactoring? I guess going from one language to another would be a more clear case of "original content" for me, in the sense of the representation of code as written, not "algorithms or business logic.
No, I'm not not looking for loopholes, I don't even have an account there.
I think what they mean by that is that it's OK to mirror code that includes LLM-generated contributions (like the Linux kernel) for your own use/work there, as long as you're not using LLMs to generate your contributions. But the Linux kernel's main development should not be done on sr.ht since it's allowing/encouraging LLM contributions.
As for the "facilitates the use..." part: They also don't want you to host your new MCP server there, even if you wrote it yourself.
That "facilitates the use of" thing is something of a wtf.
If I have a web application which includes an MCP server (as just one of many features) is that whole project banned?
What about if it has a REST API? Obviously not...
But what if that REST API is designed to be easy for LLM tools to use?
Pulling it out and isolating it, sure. Reading it within the context of the entire statement, I don't think it's a wtf at all.
I think it is very clear from the totality of the text that an MCP falls on the "not for sourcehut" side of the line. I think it's similarly clear that if you promote your REST API as "easy for LLM tools to use," the project is on the "not for sourcehut" side of the line. If your API is just designed that way, because that's a good idea and it also makes your API easy for humans to use, and you're not specifically promoting LLMs? That seems to be on the "fine for sourcehut" side of the line.
My only affiliation with them is "happy customer". I followed the discussion that fed this policy closely, and I'm happy with the clarity of the policy and balance of the implementation plan that came after that.
Personally I find the idea that describing your REST API as "easy for LLM tools to use" means you are incompatible with sourcehut very wtf, but I guess I'm incompatible with sourcehut.
I would say it's very safe that you are incompatible. If you read the whole statement, one of the major points is that they do not want to promote LLM use.
I think a fair read of the totality of your blog, for quite some time now, leads to the conclusion that you want to promote LLM use.
Their statement today says that is incompatible with their goals. It's fair for you to find that "very wtf" but hopefully their statement was clear enough that you understand where they're coming from.
Yes, I did understand that.
(I should clarify that I don't want to promote LLM use because I want more LLM use - why would I care about that? My goal is to ensure people understand what the tools can do so they can make their own informed decisions about whether they should engage with them.)
Then you should like this statement... it goes into great detail about the reasons that inform why they think engaging with LLM tools is bad for their service, bad for FOSS, and bad for society.
Yes, we probably agree on which parts are clearly on one side of the line, but my point was that without thinking deeply, I, not a heavy LLM user, could already think of some questionable ideas. That's just where my mind goes if I read ambigous rules :)
It's tailored to the linux kernel. They don't want to lose the (few quite famous) contributors who are using the service. If it was anyone else, it would probably be way more explicit.
I am a bit saddened by this decision, but on the other hand i totally understand and somewhat even agree with it... I live with the contradiction that i find LLM useful but also recognize that they are causing huge problem on the society (copyrights are not one of those, idgaf about it). I am lucky that my employer hosts some models that i can use without using the ones from big evil corps, but still... these models training have caused damages. I amwas a happy customer, but i use LLM for some projects i have there, i also have some vibecoded ones as unlisted. That's fine, i will move my projects on a self-hosted Forgejo. Or maybe some day i will join the Rebellion.
It’s expected that Sourcehut and this community will focus on AI for coding and weigh it against environmental impact (and find it wanting) however I would gently remind people that AI is quietly pushing forward medicine, safer cars and advances in many other fields. The net is positive. As always, it is a non-technological fight to make sure the benefits are seen widely.
The policy is about LLMs specifically. The "AI" which has actually made positive advances in medicine is ... not that at all. In fact, actually beneficial machine learning systems like AlphaFold have been shut down in favor of dramatically less-useful LLMs: https://www.engadget.com/2225849/google-shuts-down-alphafold/
But of course LLM companies benefit greatly from the confusion between the two different types of technologies! So it's not surprising that so many people fall for it.
Why would drug companies be using less effective tools?
The drug companies aren't the ones who decided to shut down AlphaFold; that was Google's choice. It's because Google is run by executives whose bonuses are tied to making the LLM numbers go up, not delivering real value.
If I understand correctly your base assumption is that generative AI doesn’t bring value.
From what I’ve seen personally and seen others produce it seems that it brings a lot of value to whatever field it is applied to.
Sure, I guess it's probably just a coincidence that any time someone points to the positive impacts of "AI" with concrete real-world examples it's always classic machine learning techniques and not LLMs. (or if it is LLMs, it's something that looks impressive at first glance but doesn't hold up to scrutiny, gets retracted three months later, etc)
I remember back during the "torture debate" after 9/11 when folks said "torture doesn't work" I always wondered "if it did work would you be willing to admit it and say it's wrong anyway?".
So, if LLMs clearly did "work well" by some reasonable metric, for some particular scenario, would you be willing to admit it and say that using them is wrong anyway?
If you're asking me personally, I can point you to this document I wrote in the context of whether LLMs should be used to develop Emacs: https://human-emacs.org/#:~:text=effective
We are not here to discuss whether LLMs are effective at what they are claimed to be able to do; their effectiveness is not at all relevant to the question of whether their use can be part of a principled software movement dedicated to user empowerment.
I mean, yeah there are much stronger arguments than "it doesn't work", but when I see someone making a bad argument that it does work, I can't help myself. =)
So, if LLMs clearly did "work well" by some reasonable metric, for some particular scenario, would you be willing to admit it and say that using them is wrong anyway?
I'm not quite ready to draw a clear line in the sand, but this is where I lean.
I've given frontier models a fair chance, despite my own reservations with the bad things they enable, the bad things they cause, and the bad things caused by training them. I can no longer deny their utility. If we were in a future where they were just running on my GPU, then I'd probably be using LLMs a lot more (or if just as much, I'd be feeling much better about my use).
Right now, when I experiment with them, I try to use as little as possible, even at the cost of my own productivity. Still I can't help but feel like I may end up on the wrong side of history. I find many of the reasons SourceHut (and others) cite convincing to reduce or even eliminate my own frontier LLM usage.
I'm not sure if you were trying to be glib, but I actually think your torture point is a good analogy. It's a question of ends and means, and for me when the means involve (plausible) human suffering, the ends become hard to justify. But like too many of these hard questions, there is enough deniability (do LLMs really use a lot of electricity?) and fuzziness (what if LLMs cure cancer?) to cloud the average person's judgement, such that they would think, "Well I don't know what the right answer is." And when that happens, they just got with the flow. (to be clear, this is more or less where I'm at; I don't really think of myself as having any moral high ground here).
So, if LLMs clearly did "work well" by some reasonable metric, for some particular scenario, would you be willing to admit it and say that using them is wrong anyway?
I like that question. I, for one, both find it likely that they “work well” “for some particular scenario[s]” and nevertheless refuse to engage in ‘agentic development’ regardless of how effective or ineffective it might be. (Yes, I do not work in the software industry, and I doubt I ever will.) This is of course not quite saying that it is wrong, but it is at least similar.
Alphafold is still in use, just maintained by a different company. The techniques that Google developed have been published, I'd be surprised if BigPharma didn't have in-house versions at this stage.
I wouldn't want a vibe-designed car or pill either, thankyouverymuch.
I find this a fascinating time. It's a chance to observe the social dynamics of the industrial revolution in person. Perhaps historians will call this the industrial revolution and the earlier one the _pre_industrial revoution. The past always changes.
To me it's strange to think that the industrial revolution is something that was and ended, rather than something that has very much been ongoing for over a hundred years.
There are definitely use cases that could be positive, but I'd need to see a lot more to believe the net is positive, at this point or in the likely future.
How about test cases generated by LLM?
Test cases are still content, so it is not permitted to generate them.
This is so stupid. LLM generated test cases is useful for catching bugs. Now people have to keep them on their own computers and not able to share it.
Oh, jeez. Anecdata here, but I've had terrible results with LLM-generated tests. They can generate "coverage", but not with any concision, nor have they been successful at generating boundary tests or analyzing or testing paths. Save the dev a half hour but end up with hundreds (or thousands) of repetitive LoC that still need to be maintained, and add marginal benefit for the test/build time.
In the post they explain some of their reasons, and the effectiveness or not of AI generated code doesn't seem to have been a factor.
Wonderful - one more reason to stay a paying SourceHut customer.
I personally look forward to a future where if I see a link to a repo that sounds interesting, instead of my current mode of debating if it's worth my time to check this out, since it's very likely slop anyway, just the fact that it's a SorceHut or Codeberg repo, that chance goes down significantly and I can be excited again to look at the cool things people built.
And people who get excited by vibecoded slop things people build with LLMs can continue to use GitHub or any of the new slop forges.
I believe this separation is good development for the software ecosystem as a whole.
This kind of arbitrarily behavior is silly. AI usage is between me and people who consume my code. Forge has nothing to do with this.
Fortunately radicle is really taking off lately.
It does involve them too; Codeberg also went into the impact it has on them. They don't want you using their resources for something that's antithesis to what they're trying to build, and projects using AI can have wildly different usage patterns. That's to say nothing of the social and environmental impact of AI. I don't see why it's wrong of them to take a stance.
Projects which utilize and intend to continue utilizing AI assistance after the policy change takes effect will be treated the same as most cases of ToS violation
I admire their courage, but also feels bad when a hosting platform making itself less relevant in the storm of this age.