• Noteworthy: They crawled only the default branch HEAD and inlined all source content.

    • The file contents are included inline. The decoded UTF-8 source text is embedded directly in the dataset, so it is fully self-contained — you can start training the moment the download finishes.
    • It reflects the state of GitHub in August 2025. The corpus is a direct crawl of GitHub repositories at their default-branch HEAD, capturing roughly two additional years of open-source code compared to The Stack v2.
  • We want to give developers agency over their source code by letting them decide whether or not it should be used to develop and evaluate machine learning models.

    crawled directly from GitHub and built to pre-train code LLMs with full-repository context

    Repositories that opted out are removed from the dataset before each patch release.

    “agency”

    Which AI company will not use v1 which has all of the data but will use later patch releases instead which have less data?

  • From the linked webpage readme:

    2.1 Classify. Each file is labelled permissive (at least one permissive license detected, no conflicting non-permissive license), no_license (no licenses detected, or only non-license legal texts such as CLAs), or non_permissive. The permissive allowlist follows the Blue Oak Council list plus licenses categorized as Permissive or Public Domain by ScanCode. Files classified as non_permissive are excluded from both released datasets.

    From https://www.bigcode-project.org/docs/about/the-stack/:

    v1.1: The three copyleft licenses (MPL/EPL/LGPL) were excluded and the list of permissive licenses extended to 193 licenses in total. The list of programming languages was increased from 30 to 358 languages. Also opt-out request submitted by 15.11.2022 were excluded from this ersion of the dataset. The resulting near-deduplicated dataset is 6TB in size.

    So MPL/EPL/LGPL are already not part of the dataset.

    So… why were they in there? Was this added for v1.1?

    “one permissive license” - So if my project includes a lib and I include the license file for that for the license notice…?

  • 4 hours

    I just followed the opt out link and they’re making you open a public issue with a Markdown list with all your repositories you want removed.

    Surely there has to be a better way to do this (probably the point).

    Also why are they storing 4.71 TB in a Git repo? How are they going to deal with removal requests?

    EDIT: It seems like they’re manually responding to the issues, wtf? There’s a perfectly fine GitHub auth system that they could use to verify everyone’s GitHub account / repository ownership

    EDIT 2: This is apperently a collaboration between Hugging Face and ServiceNow, why is my companies IT ticketing system scraping all of GitHub?

    • with a Markdown list with all your repositories you want removed.

      The repo readme linked FAQ says

      You can choose to request either (1) all repos, or (2) you can specify select repos that you own to be removed.

      so “all of them” should be acceptable

  • When I hear this company’s name I can’t get the idea out of my head that it’s related to the face huggers from Alien.

  • Am I alone in not wanting to put my username into that field? If they don’t have it will they then just decide that it’s now a good time to scrape it? Or are they going to record that it was searched?

    • 4 hours

      The right move is to private all repositories you are uncertain of that you want them to be preserved forever in an AI training set.

    • 4 hours

      They also scraped some of my assembly code of which I’m pretty sure the latest version has a major bug. Let’s hope they don’t use these models to program my new PC’s bios.

    • my commits are the reason we haven’t achieved AGI

  • 18 hours

    I never really needed any justification, but ever since AI companies just take stuff illegally, and that openly, it has become my justification to just pirate the shit out of everything.

    (Excluding indie games of developers I like).

      • That depends on the license. Music is also available on Youtube without authentication requirements but I don’t think you can just download those and do whatever you want with them.

        • Could be wrong, but the act of downloading music isn’t what gets people in trouble, it’s the uploading. When people torrent both happen, but afaik it’s only the uploading portion that is actually bad.

          • When people torrent only a part of the file is being shared by all peers. Technically only the original seeder shared the whole thing and after a few seeders it’s a tiny portion of the file.

          • I think there’s a difference between the laws for individuals and corporations. I don’t think they’re allowed to download either.

          • 6 hours

            This depends, but not because of piracy. If you have to bypass DRM to download the music, you may be violating DMCA §1201 (even if you are otherwise allowed to use the music).

            Edit: This obviously doesn’t apply to GitHub, but might to YouTube.

    • It should have been anyways. Like what the fuck were you all doing on the internet. Trying to sell your stupid art. Helping corporations steal data and build pay walls so you can earn $500/month selling your kitchy Garfield key chains. The internet should have always been about data replication and sharing. It’s too late to put that cat back in the bag. It was suppose to be stopped 20 years ago. Now we have all this stuff ruining the world and bringing back nazis. But at least the lefty capitalist artist sold some key chains

      • I fought hard for net neutrality, a lot of us did. We don’t matter.

        • Which goes to my point. You fought wrong. What i see is that the left is very likely manipulated by right wing interest groups way more than people want to admit. I think for decades now, they have targeted leftist online for issues we traditionally dominated and redirected people into areas that were very ineffective. Meanwhile they socially engineered the right side and MAGA to actually effective social engagement. After decades the left is just a dead in the water idea with people who no longer know how to use the internet correctly for social engineering and engagement. The only time the left rallies is when the effort is the most high effort, high energy, low reward movement people could possibly imagine.

          The left in the past were intelligent intellectual building and innovating things. That is no longer the case. We’re resting on the laurels of the best and looking around at lemmy should make it very obvious how true this is.

          The sad reality i think people need to understand its the MAGA isn’t winning just because of money. They’re wining because they’re putting effort in areas that the left don’t even realize are important. They are playing chess and the left aren’t even playing because competition makes the left feel anxious.

          I have multiple people in my life on the right who spend all their time online posting and networking and planning. They will shit post all day. Between the 3 of them, they probably create tons of content. Let alone sharing and promoting others content.

          People on the left I know will read an article. Can’t be bothered to share or even upvote. Maybe they’ll write a comment like “This sucks, Trump is stupid” and then they go look for star trek memes all day. Give this behavior 20 years for the kids today to grow up. The global cultural image of the left right now is a weak, gutless screaming loser who nobody wants to admit to being outside of small circles. Kids today hate the left. It’s going to get so much worse.

            • Me too.

              My point here isn’t to shit on the left just to shit on them. It’s to at least get discussion if not find others who see it too. I think we’re asleep. Maybe hoping if we just play the ethical long game that maybe it’ll all return. In my mind we’re standing on the beach watching the tide recede after an earthquake. Like most thing stuff is weird, but they’re not really tracking that they need to start acting now if it isn’t already too late.

              My hope is people get a fire under there ass and first admit that we have fucked up and it’s time to start firing up our own grass roots efforts. Download gimp. Get back on social media since we were never going to make a dent in their profits. Start using all these tools even AI to resist and present a front against these modern nazis. Play fucking dirty if we have to. People bitch about money but that money is only doing what we do for fun. Instead of obsessing about beans and moths, let’s get back to being political and taking ground.

              Lemmy could be a staging ground with the way it is built. Because when a site is a threat, they’ll use every capitalist lever they can to squash it. They’ll bring in moderation teams. They’ll bring in ads. They’ll bring in the tools we didn’t resist. And if they do, we stand up a new instance without that shit. But we gotta do something to fire us up or it is only going to get worse.

      • But at least the lefty capitalist artist sold some key chains

        Selling your shit and getting paid doesn’t make you into a capitalist. At most you’re an artisan, if you own your tools and you get paid for your final product rather than your labour hours.

        To be a capitalist you necessarily need to own capital. In the example you picked you’d need to own a factory where you underpay people to and keep the surplus from all the keychains they produce.

        And regardless of what you meant, you’re absolutely barking at the wrong tree here, market consolidation and monopolies predate the internet, and they would have always had the final say in how we shape our infrastructure and share shit online under capitalism.

        • You would be a supporter of capitalist. The capitalist needed to take the internet away from the left. It was hostile to making capital. Early days people were much more aware of defending it against capitalist which like you said, people were tracking how capitalist ruined all other frontiers and left them dried out husks that stifled originality, creativity and actual innovation. Look at the leftovers from the early days. Websites from them were focused on free use and sharing information freely, gnu, Winamp, VLC, sites like reddit, digg, Wikipedia wouldn’t exist with today’s internet if they were created today. Capitalist took over.

        • Keychain just a stand in for anything. More like how someone making videos of making key chains used patent trolls to build tools to scan all the videos they can in order to find users they can take down. Just one example. The little lefty entrepreneur was used to beat the old school leftists into the dirty on behalf of the corporate interests. Now everything is owned by corporate and we lost the internet to racist nazis. There’s a moment 20 years ago things could have been different that we’ll never get back. Frontier was new and we needed to rally around the wagon to defend the frontier. Instead we sold out.

          And now all the lefties are in the smallest corner of the internet and the rest of the internet and social media is owned by the capitalist and nazis. It all started by forgetting the roots and in favor of selling our key chains and trying to build a market rather than a collaborative space.

          • 14 hours

            What’s with the obsession with “lefties” vs nazis?? Sounds like somebody stayed on the propaganda carousel a bit too long.

            You choose what parts of the internet you want to use, so who cares if 99% is profit oriented garbage, honestly.

            People choose to publicly share their stuff for free, so of course it’s gonna be taken advantage of. That’s literally capitalism.

            • Yea it’s so crazy. Lol

              Everything is fine. Nazis are marching in streets again primarily driven by online recruitment. Billionaires are investing in removing leftist from digital spaces to facilitate this. But because I care, I’m obsessed.

              I’ll just choose to hang out here with the people who say they oppose this stuff but really, they’re just what, posting about beans and moths while nazis take over the government, March in the street and feed children their content through multiple pipelines that are growing because there’s fuck all resistance. After all the “resistance” is busy trying to decide which hole they want to hide in.

    • 4 hours

      No, it seems to only be a subset of public repo’s.
      I have like 65 repo’s and only 13 were scraped. I don’t get why they specifically scraped those though. They don’t have the most stars, they aren’t the oldest or newest, not the ones with the most forks, nor do I see a pattern based on programming language.

    • Microsoft has access, and everything is for sale. So, maybe? Probably? 🤷

  • A decade ago, if someone asked someone working on an Open Source project if they’d be ok with an AI reading their code and learning from it, they’d most likely say “yeah that sounds really cool!”

    Somehow the tech-bros have fucked up AI so much that something that should be really cool seems creepy, lame, and nefarious all at once.

    • 13 hours

      Making arguments from popular perception is never very strong. AI is cool if you actually think about it - the capability is incredible. Anything that can produce working code was going to have this ambivalent result where execs pushed it way too hard.

      • Yup, the idea is good. How this this idea is being implemented… not so much.

        • Simultaneously they have created the part I wanted from Star Trek, while making the worst possible anti star trek a reality.

          E.g.

          I want to be able to ask a computer about history, art, codeing, well anything. And be able to clarify and question and put together new ideas.

          But not by anyone owning that ability or profiting on the labor of others or causing environmental harm.

          We got the cool computer but haven’t achieved the post-scarcity part.

          I don’t think you can have one without the other.

    • I mean they’d have been ok with it because tech bros were the ones automating other people out of jobs and never thought it would come for theirs.

      The level of AI we have now was impossible science fiction a decade ago.

  • We want to give developers agency over their source code by letting them decide whether or not it should be used to develop and evaluate machine learning models.

    fuck them seriously; if you want to do that then don’t steal the repositories in the first place.

    • Meanwhile at work we just had a training course that specifically said doing “opt out” instead of “opt in” violates the principle of informed consent.

      • Notice how a shit load of these people keep turning up to be rapists and pedophiles… They have no shits to give about informed consent. In their mind you don’t even have the right to the same agency they do.

    • Kinda hope it uses my code. It’s so terrible there’s no doubt it will make the resulting code from the model worse even if the impact is miniscule

      • 3 hours

        They cloned a few projects I’ve made that rely heavily on a library I also made, I’m only pulling out the library.

      • I just opted out of all my repos except the God awful ones from middle and highschool. Those are basically prompt poison so fuckem

    • Unless I’m mistaken, this wasn’t written by the folks that scaped GitHub in the first place, someone just wrote a small tool to semi-automate the process of searching the scraped dats, and submitting a GitHub issue to have it removed.

      • it’s pretty clear from the language of the site, the fact that it’s on the hugging face domain, and the fact that the github organisation for the “opt out” makes it clear it’s hugging face.

      • It’s not, but it may be violation of licenses. And also, if it has personal information on it, that’s probably illegal under the GDPR.

        • but it may be violation of licenses

          They excluded code with non-permissive licenses apparently:

          Each file is labelled permissive (at least one permissive license detected, no conflicting non-permissive license), no_license (no licenses detected, or only non-license legal texts such as CLAs), or non_permissive. The permissive allowlist follows the Blue Oak Council list plus licenses categorized as Permissive or Public Domain by ScanCode. Files classified as non_permissive are excluded from both released datasets.

          also, if it has personal information on it, that’s probably illegal under the GDPR.

          It’s all public so I would be extremely surprised if that were the case.

        • I’m pretty sure they just cloned the repos. That’s how GitHub is designed to work. Have you never cloned a repo from GitHub?

              • 4 hours

                It doesn’t seem that way. My list contains several repositories that don’t have licenses, even some with GPL.

              • so if you are licenced under MIT and they use your code, they publish your copyright header?

                • Yes. If they train AI from your code? No, but the legality of that is yet to be settled and definitely leaning towards “it’s fine”.

  • The best way to opt out is by not using GitHub. Also opts you out of Copilot and a bunch of other stuff.

    • Other git hosts are also getting scraped, and have had to implement counters because of it. For example, this is the kind of thing Codeberg shows crawlers. I’ve even seen people who self-host complaining about getting overloaded because of bots scraping their forge

      • I’ve put Anubis before most of my website, including my forgejo instance. For the projects hosted there, which is not all, I can only hope that that’s enough.

        I like to have the visibility and CI of GitHub. But this sucks ass.

    • note that former users would have needed to remove their GitHub data before August 2025 to not be in this dataset

    • When I back something up, I save a copy and add “backup” to the name… Because I’m advanced.

      If I’m feeling really good and healthy, I’ll even put it on a usb stick.

  • A little bit infuriating since huggingface itself requires login to access a large portion of the content on their site

  • Pretty sure all my repos are MIT licensed for the betterment of everyone, but I’m not on the list! So I guess I’m not good enough, or they are failing to follow the attribution clause of it.

    • My dotfile repo is there and it doesn’t have a licence. Meaning it’s technically not open source. Didn’t stop them

    • Strange because all of my MIT repos are listed - all the GPL ones are excluded.

      • Mine are all GPLv3 or forks of other repos and they are listed. I’m sanguine because the license allows for study and if it’s good enough for humans I don’t see why it’s not for clankers.

        • For me, and a few other projects I checked, it only has non-GPL repos. But it also does not have everything that isn’t GPL, despite the repos being much older than the cut-off date. But it does have repos without a license, which they are simply not allowed to copy.

          I wonder if those repos have been deduplicated, and one of the forks (on some other person’s account) is included instead. Unfortunately you can only search the first 5M records via the website, and I don’t have time to play around with the API at the moment, so I could neither confirm nor deny that possibility