The Era of Software Quality, or the Era of Ostriches?
In the software development world, secure coding has been a consistent challenge. GNOME, a popular open-source project, is no exception – it is written using unsafe programming languages like C, C++, and Vala, which make it easy for developers to make mistakes that can have severe consequences for users. Despite the developers' best efforts, writing secure code with these languages remains exceedingly difficult, even for experienced programmers.
In 2024 and 2025, the author of this account delivered talks at the GUADEC conference, where they expressed the belief that humans were inherently incapable of writing software properly. They were skeptical about relying on AI to improve software quality, but the situation has since drastically changed. AI technology has dramatically improved, and now offers the ability to perform vulnerability scanning on software to identify security flaws.
The author firmly believes that without AI-driven vulnerability scanning, maintaining the quality of software in 2026 would be impossible. Numerous bugs have been discovered in critical projects like GLib and fwupd, and failure to scan these projects would be an unfair disservice to users. Moreover, the increasing Linux user base has made Linux systems more attractive targets for attackers, further emphasizing the need for robust security measures.
AI has also made it easier than ever to create working exploits, which were previously unimaginable. The current AI-enabled vulnerability reports have drastically improved in quality, although they still present challenges for maintainers. These reports are often verbose, overly detailed, and occasionally inaccurate or fabricated.
Despite these issues, the author argues that accepting and dealing with AI-generated vulnerability reports is essential. Prohibiting AI-generated content in issue reports would be counterproductive, as most vulnerability reports are now AI-generated. Instead of attempting to rewrite AI-generated reports, the author recommends that maintainers acknowledge the necessity of these reports and work with them to address the identified issues.
The trend of increased CVE (Common Vulnerabilities and Exposures) reports in GNOME projects is clear: after a period of minimal reporting, there has been a significant rise in the number of CVEs identified in recent years. AI has been a major contributing factor to this increase, although other factors also play a role. As the software quality landscape evolves, the author urges the GNOME community to embrace AI-driven vulnerability scanning and adapt to the new reality of AI-generated vulnerability reports.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.