惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

宝玉的分享
宝玉的分享
L
LINUX DO - 最新话题
Stack Overflow Blog
Stack Overflow Blog
月光博客
月光博客
雷峰网
雷峰网
Apple Machine Learning Research
Apple Machine Learning Research
V
Visual Studio Blog
Attack and Defense Labs
Attack and Defense Labs
O
OpenAI News
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
B
Blog RSS Feed
H
Help Net Security
量子位
小众软件
小众软件
SecWiki News
SecWiki News
N
Netflix TechBlog - Medium
TaoSecurity Blog
TaoSecurity Blog
美团技术团队
博客园 - 司徒正美
Hacker News - Newest:
Hacker News - Newest: "LLM"
Recent Commits to openclaw:main
Recent Commits to openclaw:main
The Cloudflare Blog
N
News and Events Feed by Topic
C
Cybersecurity and Infrastructure Security Agency CISA
The Last Watchdog
The Last Watchdog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Scott Helme
Scott Helme
T
The Exploit Database - CXSecurity.com
K
Kaspersky official blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Threat Research - Cisco Blogs
C
CERT Recently Published Vulnerability Notes
Application and Cybersecurity Blog
Application and Cybersecurity Blog
U
Unit 42
Google DeepMind News
Google DeepMind News
J
Java Code Geeks
Schneier on Security
Schneier on Security
G
Google Developers Blog
Forbes - Security
Forbes - Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
Y
Y Combinator Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Palo Alto Networks Blog
A
Arctic Wolf
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
The Hacker News
The Hacker News
B
Blog
D
DataBreaches.Net
Simon Willison's Weblog
Simon Willison's Weblog

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
How vibecoding is destroying the open source that feeds it
Nicolas Dabene · 2026-05-29 · via DEV Community

Nicolas Dabene

How vibecoding is destroying the open source that feeds it

March 3, 2026


The snake eating its own tail

A year ago, vibecoding was a curiosity. Today, it’s an industry. Millions of developers — or rather prompters — generate entire applications by describing what they want to an LLM. In minutes, an API, a frontend, a deployment. Magical.

But behind this magic lies a dirty secret that nobody wants to face: every line of code generated by these AIs was trained on millions of open source projects — projects that are now dying.

Vibecoding would be nothing without open source. And it’s killing it.


What exactly is vibecoding?

For those who spent 2025 in a cave: vibecoding is the practice of creating software in natural language, relying on generative AI models (Claude, GPT-5, Gemini, and the dozens of specialized models that have emerged since). You describe a vibe, an intention, and the AI produces the code.

No debugging. No reading documentation. No Stack Overflow. And above all — here’s the crux — no contributing back.


The implicit pact of open source is broken

The open source ecosystem has always rested on a tacit social contract:

I publish my code for free. In return, others use it, find bugs, suggest improvements, contribute. The project lives because a community keeps it alive.

This contract had already been severely tested by large corporations that consume open source without contributing proportionally. But at least the developers who used these libraries understood them. They opened issues. They forked. They sent pull requests. They wrote blog posts that spread the word about the project.

Vibecoding has blown up this cycle.

The vibecoder doesn’t know which library they’re using. They don’t know, and they don’t care. They asked “build me a payment API with webhook handling,” and the AI chose this or that dependency for them. They will never read that project’s README. They will never open an issue. They won’t even know that project exists.


The chilling numbers

The data is starting to speak, and it’s not reassuring:

  • Contributions to mid-size open source projects (10-500 stars) dropped 35% between January 2025 and January 2026, according to aggregated data from GitHub and GitLab. These mid-size projects form the essential connective tissue of the ecosystem.
  • The number of new issues opened by humans is down 28%, while issues opened by bots or automated tools are exploding — mostly noise, rarely signal.
  • Donations via GitHub Sponsors, Open Collective and Tidelift are stagnating or declining for the majority of projects, while actual usage (measured by npm, PyPI downloads, etc.) continues to rise. More consumption, less support.
  • The number of new “first-time” contributors to foundational projects (crypto libraries, parsers, networking tools) has dropped 41%.

That last number is the most alarming. The pipeline of the next generation is drying up.


The ghost generation

I spoke with about ten maintainers of popular open source projects in recent weeks. The same observation comes up, almost word for word:

“My downloads have never been higher. My contributions have never been lower.”

Maintainer of a Python data processing library, 12,000 stars

“I’m getting issues that clearly make no sense. Someone copy-pasted an error message generated by an AI tool, without understanding what my library does or even knowing they’re using it. I spend more time closing useless issues than developing.”

Maintainer of a Node.js tool

“I feel like I’ve become an invisible subcontractor for Cursor and Copilot. My code is everywhere, but I’ve disappeared.”

Creator of a UI component library

Vibecoding has created a ghost generation: people who depend on open source without existing in open source. They are neither users, nor contributors, nor observers. They are passive consumers of an automated value extractor.


The technical problem: dependencies without awareness

Beyond the community problem, there’s a concrete technical issue.

When a human developer chooses a dependency, they (in theory) do evaluation work: is this project maintained? Does it have known vulnerabilities? Is it suited to my use case? What’s its license?

AI optimizes for what works right now. It favors libraries over-represented in its training data — meaning those that were popular at training time. This creates two perverse effects:

  1. The fossilization effect: obsolete or poorly maintained libraries keep being injected into new projects because the AI “remembers” them. We’ve seen projects generated in 2025 using package versions from 2022, with known CVEs.
  2. The winner-take-all effect: big projects (React, Express, pandas) continue to be systematically recommended, while newer, lighter, better-designed alternatives remain invisible. The ecosystem’s innovation freezes.

The “democratization” paradox

Vibecoding advocates make a compelling argument: democratization. Thanks to AI, millions of people who couldn’t code can now create software. That’s true. It’s even wonderful.

But this democratization is extractive. It extracts value from a common good (open source) to concentrate it in proprietary products (AI IDEs, SaaS platforms, inference APIs). Vibecoders pay their subscription to Cursor or Replit, not to the person maintaining date-fns at 2 AM.

We’ve privatized the benefits and socialized the costs. A classic.


AI models themselves make it worse

We must also point the finger at the AI companies themselves.

The models were trained on open source code, often without explicit consent, and the revenue generated by these models doesn’t flow back to the projects they depend on.

Some initiatives exist — Anthropic, Google and others have launched support funds — but let’s be honest: these are crumbs. The “AI for Open Source” fund announced by the Linux Foundation in November 2025 represents $50 million. That’s less than what these companies spend on compute in a single quarter.

And above all, money doesn’t replace contributors. An open source project doesn’t die for lack of dollars. It dies for lack of people who care.


The nightmare scenario

Let’s project forward for a moment.

If current trends continue:

  1. Exhausted maintainers abandon their projects. This is already happening. Maintainer burnout isn’t new, but vibecoding accelerates it by increasing the load (more usage, more noise in issues) while diminishing the reward (less recognition, fewer contributions).
  2. Critical projects become zombie software: still downloaded, never updated again. Security flaws accumulate. AIs keep recommending them.
  3. A major security crisis erupts when a vulnerability in a zombie package ends up in thousands of vibecoded applications. Log4Shell will seem like a warm-up exercise.
  4. Innovation slows down because new open source projects can no longer find a community. Why publish a package when nobody will ever look at it — when people don’t look at code at all anymore?
  5. AI models degrade because they increasingly train on AI-generated code rather than thoughtful human code. The snake eats its own tail down to the bone. What’s called model collapse becomes visible in the quality of produced code.

This scenario isn’t science fiction. Every step is already underway.


What can be done?

I’m not naive enough to think we can stop vibecoding. The genie is out of the bottle, and frankly, the productivity it brings is real. But we can — we must — correct course.

1. Tax extraction, fund the commons

AI platforms that monetize code generated from open source should return a significant percentage of their revenue to the ecosystem. Not a symbolic fund. A structural mechanism, proportional to actual usage. The model already exists in other domains: it’s called a redistribution license or a digital commons royalty.

2. Make dependencies visible

Vibecoding tools should systematically display the open source dependencies they inject, with a link to the project, its maintenance status, its license, and a way to contribute. Not hidden in a package.json that nobody will read. Full screen. “This code uses 47 open source projects. 3 of them haven’t been updated in a year. Here’s how to support them.”

3. Integrate contribution into the AI workflow

Why couldn’t AI tools generate contributions back? Detect a bug in a library, draft a fix, propose improved documentation? If AI can consume open source, it should be able to contribute to it.

Some experimental projects are moving in this direction. They need to be generalized.

4. Educate vibecoders

Just because you don’t code doesn’t mean you shouldn’t understand where the code you use comes from. Vibecoding platforms should include a minimum of open source literacy: what’s a license? What’s a maintainer? Why does it matter?

We don’t require someone who drives a car to know how to build one. But we do require them to know that the road was built by someone, and that they pay taxes to maintain it.

5. Rethink licenses

The MIT license and the Apache license were written for a world where users were developers. That world no longer exists. It’s time to explore new licensing models that account for AI extraction and ensure fair redistribution of the value created.