• Lost_My_Mind@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 days ago

    Hold on …

    Are you saying all software hosted on github is infected with copilot? Or am I misreading the situation?

    • renegadespork@lemmy.jelliefrontier.net
      link
      fedilink
      English
      arrow-up
      6
      ·
      4 days ago

      Your confusion is understandable since MS has called like 4 different products “Copilot”. This refers to the coding assistant built into GitHub for everything from CI/CD to coding itself.

      All code uploaded to GitHub is subject to being scraped by Copilot to both train and provide inference context to its model(s).

      Basically having your code in GitHub is implicit consent to have your code fed to MSs LLMs.

      • Zwuzelmaus@feddit.org
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        4 days ago

        All code uploaded to GitHub is subject to being scraped

        No kidding: That was literally my very first thought back in the days when I learned that M$ has taken over GitHub.

        (Copilot did not exist then)

      • The Octonaut@mander.xyz
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        4 days ago

        No, it isn’t.

        “Basically” your vibes aren’t an actual answer. Businesses are not forking over millions to give away their code.

        You can have conspiracy theories about it using the code anyway (I’m particularly confused about your use of the word “scrape” which tells me you don’t know how AI training works, how hosting a website works, or how scraping works - maybe all three?) but surreptitiously using its competitors’ code to train CoPilot would be a rare existential threat to Microsoft itself.

        Does GitHub use Copilot Business or Enterprise data to train GitHub’s model?

        No. GitHub does not use either Copilot Business or Enterprise data to train its models.

        https://github.com/features/copilot#faq

        • Kilgore Trout@feddit.it
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 days ago

          FAQs are not legally binding. If you want to quote something, then do privacy policy and terms of service.

          • The Octonaut@mander.xyz
            link
            fedilink
            English
            arrow-up
            0
            arrow-down
            1
            ·
            4 days ago

            It’s in every enterprise and business contract signed with them. The FAQ was just the first result on Google. Its obviousness shouldn’t even require that much. It’s extremely clear how few of Lemmy’s “technology” crowd have any contact with adult life.

            • brennesel@discuss.tchncs.de
              link
              fedilink
              English
              arrow-up
              1
              ·
              4 days ago

              Why are you referring all your answers to GitHub Enterprise and corporate contracts? Nobody here is talking about that, as the news is about an open source project. Public GitHub and GitHub Enterprise are fundamentally different.

              You accuse others of responding based solely on “vibes,” but you do exactly the same thing in the opposite direction. And yet, of all people, you’re saying we don’t act like adults.

              • The Octonaut@mander.xyz
                link
                fedilink
                English
                arrow-up
                0
                ·
                4 days ago

                All of the responses are saying that Github reads all code. Github public and Github enterprise are products of the same organisation. Many are even saying they will consume enterprise data anyway despite contracts not to. As I said in my first response, there aren’t many things that would ruin Microsoft’s ability to operate but this is one.

                What vibes do you think I’m going off?

                • dreamkeeper@literature.cafe
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  2 days ago

                  Lemmy is completely unhinged on any AI topic. You can’t engage rationally with these people.

                  They have zero evidence that any of their accusations is really happening but they’ll insult and bully people over it anyway.

                • brennesel@discuss.tchncs.de
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  3 days ago

                  What vibes do you think I’m going off?

                  What I meant was that you read the comments, identified inconsistencies from your point of view, and then responded in a confrontational manner without including the whole context.

                  You do have some good points. But instead of opposing everything that has been said, you could have differentiated much better.

                  For example:

                  • Public repositories on github.com are definitely used for AI training
                  • Private repositories on github.com are suspected of being used for training
                  • Github Enterprise Cloud is probably contractually protected
                  • Github Enterprise Server is the most secure of all options due to contracts and self-hosting (and therefore the only valid best option for enterprises with proprietary code)

                  All of the responses are saying that Github reads all code.

                  The first comment explicitly mentions “hosted on GitHub”, which at least excludes GitHub Enterprise Server, which is self-hosted.

                  The article is about an open source project that, by definition, uses public repositories.

                  Github public and Github enterprise are products of the same organisation.

                  Coming from someone who tells others that they first need to deal with “adult life”, I find this statement surprising. I work for an international company and manage several Github orgas with hundreds of repos. Whether the code is stored on github.com or on our own Github Enterprise server is highly relevant and makes a huge difference.

                  • The Octonaut@mander.xyz
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    arrow-down
                    1
                    ·
                    3 days ago

                    All code uploaded to Github is scraped

                    This is the very simple statement that I was responding to, along with the next line about how using Github is implicit consent to feeding your data to an LLM. If the poster wants nuance, they are free to provide it themselves. You can see in subsequent responses there is none.

                    Of course them being different matters. That’s my point. Not all code uploaded to Github is being fed into an LLM. It is not consent if you are signing a contract demanding that something not be done. It’s preposterous even at a surface level.

                    Github Enterprise Server is different from Github Enterprise Cloud, which is what I was talking about, and which is explicitly not used for training LLMs, and if it were, would absolutely kill Github as a product and likely mire Microsoft in years of litigation.

                    Frankly I don’t know of any software company using Github Enterprise on-prem but I suppose there are probably some CEOs out there who haven’t taken the OpEx pill. Maybe deep in the rainforest with Mokele-Mbembe. Certainly in my sliver of the tech industry, telecoms, the idea of owning a server is akin to having a deskphone and an outgoing mail room.

                • Paulemeister@feddit.org
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  4 days ago

                  Dude AI companies do not give a fuck about the law. It’s hard to prove a specific piece of data was used to train a model so they put everything in they can. There’s literally a lawsuit about this, where Microsoft and others claim using code on GitHub to train is fair use.

                  As far as I can tell this lawsuit is about copyright infringement of open source code, but as we where talking about an open source project leaving GitHub because of this, that’s what’s relevant.

                  I myself would not be surprised if they could not withstand the urge to put more high quality code from enterprise users into their training data, but as they are not suing and we don’t know their code, that’s speculation.

                  • dreamkeeper@literature.cafe
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    2 days ago

                    So your first two paragraphs admit that you aren’t refuting anything the other guy said. He was clearly talking about enterprise contacts, not the free tier of GitHub which is completely different.

                    It’s insane how aggressive you guys are being about this despite having zero evidence to back you up other than “corporations lie”, as if other lying corporations don’t have their own small army of lawyers writing these contracts. Those guys will instantly file a lawsuit the moment they suspect their company’s data is getting eaten by copilot.

                    It would be an incredibly stupid move by Microsoft to do that, especially because it would put all their other contracts with that company at risk (eg office 365, exchange, etc)

        • RichardDegenne@lemmy.zip
          link
          fedilink
          English
          arrow-up
          0
          ·
          4 days ago

          If you’re gullible enough to believe an FAQ coming from Github themselves, then I have bad news for you.

          • The Octonaut@mander.xyz
            link
            fedilink
            English
            arrow-up
            0
            arrow-down
            1
            ·
            4 days ago

            “Gullible” is not a thing you can be when somehow has signed a contract with you… that’s why contracts exist.

    • ExLisper@lemmy.curiana.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 days ago

      I guess it’s about copilot scanning the code, submitting PRs, reporting security issues, doing code reviews and such.