Damnit keepassxc is slop now? Of all things they’re putting untrustworthy code into a password manager?
Was not aware of this situation so thank you for the share

There are no AI features inside KeePassXC and there never will be!
https://keepassxc.org/blog/2025-11-09-about-keepassxcs-code-quality-control/
this seems like a proper use of AI to me?
Seems like they’ll happily accept 100% AI-coded slop PRs, though they at least have one human look at first I guess?
The fact they think AI-code is equally valid/safe code is a problematic stance, I’d argue.
Forgive my ignorance, but isn’t AI really good at finding vulnerabilities nowadays? And hasn’t GrapheneOS argued that AI is good at finding vulnerabilities?
I mean, vulnerabilities and contributing code are pretty different things. But most of what I know about AI finding vulnerabilities is that their abilities and achievements are hugely overhyped, as evidenced by the fact that there hasn’t been any consequent mass-hacking, I’ve seen a few niche things unveiled, but at no particularly faster rate than usual.
I’ve no idea about GrapheneOS or the people that run it.
-
Four months ago a vulnerability was found using an LLM on the piefed instance and that caused a massive shit show. It is definitely not just hype. The implication here is that anyone can throw the source code of an open project to an LLM and look for vulnerabilities
-
GrapheneOS recently got into a controversy because of their use of AI in the defense and identification of threats. The reality is that when your opponents are using AI to attack, you need AI for defense too
-
While contributing code is different, what does this actually mean for projects? How are you going to enforce and verify not using AI among your coworkers or contributors? It seems the keepass devs already realize the futility of this practice so they just have them specify which code was written by AI
Don’t get me wrong, I’m not defending vibe coding, I’m just realizing that fighting this is just a losing war
I don’t see anything here that counters the idea we should be fighting or discouraging AI use in software. I’ll be honest and say I’m struggling to understand what your point really is.
- One vulnerability found four months ago is nothing new. Random script kiddies who know nothing have been finding exploits since the invention of the computer. When this becomes actually notably more of a regular occurrence, I’ll be more worried.
- Again, I don’t know about the GrapheneOS lot. I really don’t think their position or use of AI is relevant. Thousands of ubiquitous software projects don’t use AI for “defense”, despite many people looking for exploits, yet there’s no big uptick in issues. So I’m not convinced AI is useful for “defense” either, but that’s a separate question.
- You don’t need a magical oracle to ban stuff. Some people will secretly use it; if/when that becomes apparent, you can enforce it. We ban fascists from Hexbear, not by mind-reading, but by just… banning them when they behave fascistic. Same deal.
-
It can be. The issue usually lies in having untrusted code contributed by people who may or may not know what they’re doing. Or, worse, maliciously writing code with AI assistance to insert vulnerable code which the human maintainers are less likely to spot because
- More AI use = higher quantity of code submissions
- More code submitted = more code to maintain and audit
- More code to maintain and audit = More chance of human error or reliance on LLMs (which brings us back to 1.)
I think there’s ways AI can help software engineers accelerate the shitty work and otherwise keep working as before, but there’s big wave of bozos seeing LLMs do one or two cool things and just throwing it all to the sometimes breaks ur code machine. As with all things having some dialectical thinking helps with adapting moreso than blind end-of-history rhetoric from the likes of anthropic et al.
In theory it’s not the worst, but I’m not very happy about it either.
Oh hell yes, thank you.
When the KeePassXC dev team stood their ground, as an alternative for desktop I’ve been using https://flathub.org/en/apps/org.gnome.World.Secrets which has been good.
I’ll see if it’s still maintained next year.
I must be out of the loop, what happened with KeyPassXC?
Can someone illustrate me on why I should change from KeePass2, the one I’m currently running?
All of these shitty forks that will be left unmaintained in the next few months scream to me like those reactionary anti-DEI, anti-COC or other any other anti-whatever forks. The likes of Xlibre and maybe even Devuan.
Even if the goals are commendable, it all looks so pointless. Contrarianism doesn’t really work that well in FOSS from what I’ve seen and unfortunately a lot of devs want their little slop factories. Debian being a sad recent example.









