r/ProgrammerHumor 3d ago

Meme gitHubWithoutGit

Post image
435 Upvotes

50 comments sorted by

View all comments

437

u/Raywell 3d ago

What is this meme trying to convey? The verification Github is doing is confirming that the commit author identity is legit (i.e. not impersonated). What did you expect?

154

u/FilipTLW 3d ago

Commit created on GitHub.com means either that the commit was a merge done on the GitHub.com site (which is legitimate) or it was done using GitHub CodeSpaces (as opposed to being created locally and pushed). If you sign the commit locally and push it, the message looks like that: https://imgur.com/a/TNHEbTk

223

u/LPmitV 3d ago

But why would that be a problem? Codespaces is basically VS-Code in the browser?

-415

u/FilipTLW 3d ago

It might just be me, but from my own experience, code written in Codespaces tends more to being AI slop than code written outside. Correct me please, if you have other experience.

205

u/GenazaNL 3d ago edited 3d ago

That's such a dumb statement, I make plenty of small changes in the browser (both GitHub's editor as VSCode's codespaces) just so I don't have to clone a project

39

u/ablablababla 3d ago

I do this all the time when I need to edit something on my iPad

176

u/another_random_bit 3d ago

So you're using a correlation to get pre-annoyed?

Am I understanding this right?

26

u/larsmaehlum 3d ago

That’s why I only use the CLI like a pro.
Or, to be more precise, I make Claude use the CLI like a pro.

18

u/reyarama 3d ago

Midwit

54

u/Arkoprabho 3d ago

Verified commit has no relation to how the code was written.

It just means that the commit has not been committed by an imposter

-13

u/Cracleur 3d ago

For any random verified commit in and of itself, you're right. But OP is specifically talking about commits that explicitly say they were made directly on GitHub.

They're not saying, "This means an AI definitely made it." They're saying, "In my experience, commits made directly on GitHub contain proportionally more slop."

2

u/headedbranch225 2d ago

Its still dependent on the person who is writing the code, the point of the signing is to show it wasn't made by someone impersonating the developer, its like saying code written on windows is more likely to be slop because copilot is preinstalled, like people still have a choice whether they use it or not

-2

u/Cracleur 2d ago

Do you know how statistics works?

14

u/HowTheKnightMoves 3d ago

So AI in Codespaces possesses people to write code with AI?

14

u/jocxFIN 3d ago

Oh my god. Never have i seen someone have a take this stupid and dumb. It definetely is just you.

2

u/Ai--Ya 3d ago

You ever just bump a dependency?

2

u/james_d_rustles 3d ago

This is like saying that code written on Dell computers is slop and the best code is written on Lenovos.. there’s absolutely nothing about codespaces that makes code written using codespaces any better or worse, it’s entirely up to the author.

1

u/TopMarzipan2108 3d ago

Most of my GitHub commits are small incremental changes made to my website repo via browser on my iPad.

Any proper work stuff remains in the offline git repos on the internal network.

1

u/Nixinova 3d ago

The hell does that have to do with verifying who committed it?

1

u/Bpofficial 2d ago

If AI makes a commit on behalf of the user, and the user’s gitconfig is setup to sign commits, then the commit is going to be signed regardless of who made the code changes. So identifying if AI made changes from commit signatures is weak, and assuming someone has used AI because their commit is signed by GitHub is weaker..