oss-sec mailing list archives

Re: Some Changes to GNOME Security Tracking


From: Collin Funk <collin.funk1 () gmail com>
Date: Fri, 31 Jul 2026 10:43:00 -0700

"David A. Wheeler" <dwheeler () dwheeler com> writes:

On Jul 30, 2026, at 10:02 PM, Peter Gutmann <pgut001 () cs auckland ac nz> wrote:

Alan Coopersmith <alan.coopersmith () oracle com> writes:

2) The GNOME security team will no longer forward vulnerability reports
 to projects that ban AI-generated content, since most reports they
 get these days have at least some AI-generated content.

So you've got a bunch of projects where people are clamoring for them to
reject anything that might have been touched by AI, and another bunch of
projects where people have decided to refuse to take part in anything that
rejects things that have been touched by AI.

To be fair: Michael Catanzaro is saying he's simply abiding by the request of
those projects. They don't want to receive any AI-generated content,
and since most vulnerability reports have AI-generated content, Michael won't send them any.

Of course, that's absurd. It's appropriate to reject *bad* reports,
but people should be open to truth wherever it comes from.
Projects that reject truthful security reports are putting their users at risk.

I'm sure the projects banning AI submissions don't like it either.

It takes time to filter out the "bad" reports if you actually care about
checking each of them. This is especially true when AI submissions are
unnecessarily verbose, which is true for a large portion of them. They
also tend to exaggerate the security implications of bugs, and are
annoying in various other ways.

Collin


Current thread: