GNOME developer: AI vulnerability scanning is now mandatory for secure software
The era of software quality, or the era of ostriches?
Humans are bad at writing secure code, and GNOME developers are no exception. AI has improved considerably, and offers a magic fairy wand solution: we can now simply ask a language model to look for vulnerabilities in our software. There is zero hope of maintaining quality software in 2026 without AI vulnerability scanning. Any claims to the contrary are unserious and delusional.
- nottorp
Hey does that mean they'll use "AI" to allow users to customize the desktop environment again?
- tonymet
why not have AI do more quality control?
- greatgib
> GNOME is primarily written using unsafe programming languages where simple mistakes in our code lead to devastating consequences for our users, and we make these mistakes all the time. No matter how much we try, GNOME developers will fail write secure code when using unsafe languages like C, C++, or Vala: it’s just too hard for even experienced developers to do properly.
Once I saw that I knew that this article was a ridiculous stack of bullshit.
Gnome might have some bugs and shortcomings but now millions desktops are using Gnome based window manager for decade and the world didn't collapse yet.
And let's not forget the ridiculous assumption that you can't handle a software quality without using AI...
- someonebaggy
Everything coming from GNOME about software quality should be taken with a Strategic Petroleum Reserve of salt.
While other projects rewrite things in memory-safe ways, GNOME's response is to ask a chatbox if there are any memory vulnerabilities.
- asjq178
[flagged]