Michael Catanzaro argues that AI-driven vulnerability scanning has become indispensable for maintaining secure GNOME software in 2026: humans repeatedly introduce exploitable bugs when using unsafe languages like C, C++, and Vala, and modern language models now find many of those issues reliably. AI reports have improved since 2025 and can also surface non-security bugs, but they bring new burdens - verbosity, exaggerated severity, occasional inaccuracies and fabricated details, and an overwhelming volume that strains volunteer maintainers. Rewriting AI-generated reports is impractical at scale, so maintainers should permit AI-originated vulnerability reports rather than banning them; projects that prohibit such reports should not be dependencies for GNOME.
Concrete data back the claim: GNOME CVEs rose sharply from the low tens in 2021-2023 to 141 reported year-to-date in 2026 (normalized to ~188), and WebKitGTK saw an explosion to 305 CVEs in 2026 driven largely by bundled Skia and ANGLE issues. A short-lived GNOME bug bounty program received 298 submissions, accepted 71, and paid €183,900 (mean €2,662.99) before closing because the inflow was unsustainable. Security tracking has been paused, so official CVE counts will drop unless others assume that work.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.