Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Entire: Open-source tool that pairs agent context to Git commits (entire.io)
4 points by resiros 18 days ago | hide | past | favorite | 3 comments


From https://news.ycombinator.com/item?id=46660151 :

> Start with env args like AGENT_ID for indicating which Merkle hash of which model(s) generated which code with which agent(s) and add those attributes to signed (-S) commit messages. For traceability; to find other faulty code generated by the same model and determine whether an agent or a human introduced the fault.

> Then, `git notes` is better for signature metadata because it doesn't change the commit hash to add signatures for the commit.

> And then, you'd need to run a local Rekor log to use Sigstore attestations on every commit.

> Sigstore.dev is https://SLSA.dev compliant.

> Sigstore grants short-lived release attestation signing keys for CI builds on a build farm to sign artifacts with.

> So, when jujutsu autocommits agent-generated code, what causes there to be an {{AGENT_ID}} in the commit message or git notes?

Does Entire solve for this?

Re: AI and DevOps Traceability: https://gemini.google.com/share/4c0c79c0f136


From https://github.com/pulp for example:

> All contributors must indicate in the commit message of their contribution if they used AI to create them and the contributor is fully responsible for the content that they submit.

> This can be a label such as Assisted By: <Tool> or Generated by: <Tool> based on what was used.

But which metadata is better stored in git notes than in a commit message? JSON-LD can be integrated with JSON-LD SBOM metadata


I made this last week in my spare time, without $60m in seed funding!

https://github.com/re-cinq/claudit




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: