> On Jul 30, 2026, at 10:02 PM, Peter Gutmann <[email protected]> wrote:
>
> Alan Coopersmith <[email protected]> writes:
>
>> 2) The GNOME security team will no longer forward vulnerability reports
>> to projects that ban AI-generated content, since most reports they
>> get these days have at least some AI-generated content.
>
> So you've got a bunch of projects where people are clamoring for them to
> reject anything that might have been touched by AI, and another bunch of
> projects where people have decided to refuse to take part in anything that
> rejects things that have been touched by AI.
To be fair: Michael Catanzaro is saying he's simply abiding by the request of
those projects. They don't want to receive any AI-generated content,
and since most vulnerability reports have AI-generated content, Michael won't
send them any.
Of course, that's absurd. It's appropriate to reject *bad* reports,
but people should be open to truth wherever it comes from.
Projects that reject truthful security reports are putting their users at risk.
--- David A. Wheeler