The piece argues that AI-driven vulnerability scanning has become indispensable by 2026: humans routinely make security-critical mistakes in unsafe languages, and modern language models now find many vulnerabilities and even help build exploits. Evidence includes a dramatic rise in GNOME CVEs (from 21 in 2021 to 141 year-to-date in 2026, normalized to ~188) and a surge in WebKitGTK CVEs in 2026 (305 YTD, driven largely by bundled Skia and ANGLE analysis). AI-generated reports have improved markedly since 2025 and can detect hundreds of issues per project, offering an unprecedented opportunity to raise software quality that cannot be ignored.
The influx of AI reports, however, overwhelms volunteer maintainers: many reports are verbose, overstate severity, occasionally fabricate data, and reviewing or rewriting reports at scale is unrealistic. A GNOME bug bounty experiment illustrated the volume problem - 298 reports submitted from 2024-2026 with only 71 accepted, €183,900 paid out (mean €2,662.99) - leading to program closure. The prescription is explicit: projects must permit AI-generated vulnerability reports, maintainers should update contribution policies accordingly, and projects that ban such reports are effectively unsuitable dependencies for GNOME. Rejecting AI reports equates to turning away most current vulnerability research.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.