oss-sec mailing list archives

Re: Some Changes to GNOME Security Tracking


From: Aaron Rainbolt <arraybolt3 () gmail com>
Date: Fri, 31 Jul 2026 09:04:05 -0500

On Fri, Jul 31, 2026 at 3:12 AM Peter Gutmann <pgut001 () cs auckland ac nz> wrote:

Alan Coopersmith <alan.coopersmith () oracle com> writes:

2) The GNOME security team will no longer forward vulnerability reports
  to projects that ban AI-generated content, since most reports they
  get these days have at least some AI-generated content.

So you've got a bunch of projects where people are clamoring for them to
reject anything that might have been touched by AI, and another bunch of
projects where people have decided to refuse to take part in anything that
rejects things that have been touched by AI.

It's not that I think projects should refuse to take part in anything
that rejects things that have been touched by AI. I don't have any
philosophical problem with it at all, if one wants to reject AI, go
ahead. But if a project is intentionally not receiving security
vulnerability reports (and therefore not repairing the corresponding
issues) because the reports were AI-assisted, that means the latest
version of an application has a much higher-than-normal likelihood of
having unpatched vulnerabilities. It's just a practical measure to
avoid using such programs for processing untrusted data, and it seems
security-conscious users would benefit from knowing what projects they
need to use with care for these reasons.

--
Aaron

Just to sort things out in my mind, which of the two is the People's Front of
Judea and which is the Judean People's Front?

Peter.


Current thread: