Skip to content
Hacker News front pagebirdculture

GNOME's software quality fight: accept AI bug reports, or look away?

The Era of Software Quality, or the Era of Ostriches?

People involved in GNOME security work argue for allowing AI-generated vulnerability reports and scanning projects proactively, while stressing that AI alone is not enough and human verification and security audits are still needed. GNOME's bug bounty program closed after too many reports: 298 submitted, 71 accepted, €183,900 paid out. A Red Hat-commissioned GLib scan claimed 118 vulnerabilities, 46 of which maintainers judged not to be security defects, and the results still had unfinished deduplication.

Why it matters: GNOME's bug bounty closed under a report backlog, and the vulnerability-finding gains from AI scanning come with triage, verification and fix-review work for maintainers.

Read the original ↗Export Markdown