Skip to content
Trending storyDeveloping

GNOME debates AI vulnerability reports and software quality

1 report1 sourceupdated 3 hours ago

What happened

AI digest

An October 5 report says GNOME security contributors want AI-generated vulnerability reports accepted and projects scanned proactively, while insisting AI cannot be the only check and that human review and security audits are still needed. The GNOME bug bounty program closed after too many reports: 298 submitted, 71 accepted, €183,900 paid out. A Red Hat-commissioned GLib scan claimed 118 vulnerabilities, 46 of which maintainers judged not to be security defects; the scan results were also not fully deduplicated.

Written by AI from the coverage · updated 2 hours ago

Coverage

Follow the reports to see the story from different sides.

Oct 5
  1. Hacker News front pagePick
    GNOME's software quality fight: accept AI bug reports, or look away?

    People involved in GNOME security work argue for allowing AI-generated vulnerability reports and scanning projects proactively, while stressing that AI alone is not enough and human verification and security audits are still needed. GNOME's bug bounty program closed after too many reports: 298 submitted, 71 accepted, €183,900 paid out. A Red Hat-commissioned GLib scan claimed 118 vulnerabilities, 46 of which maintainers judged not to be security defects, and the results still had unfinished deduplication.

Heat over time

Not enough continuous observations to draw a trend yet.