Humans are bad at writing secure code, and GNOME developers are no exception. GNOME is primarily written using unsafe programming languages where simple mistakes in our code lead to devastating consequences for our users , and we make these mistakes all the time . No matter how much we try, GNOME developers will fail write secure code when using unsafe languages like C, C++, or Vala: it’s just too hard for even experienced developers to do properly. The above paragraph is taken from the abstracts of my GUADEC 2024 and 2025 talks. At the time, I thought failure was inevitable: we humans were so bad at writing software that we had no chance to do it properly, and I certainly would not have trusted an AI to do better than a human. But the landscape today is completely different than last year. AI has improved considerably, and offers a magic fairy wand solution to this problem: we can now simply ask a language model to look for vulnerabilities in our software. They are quite good at this. There is zero hope of maintaining quality software in 2026 without AI vulnerability scanning. Any claims to the contrary are unserious and delusional. The tremendous quantity of bugs found in our best-maintained projects, like GLib and fwupd, should speak for itself. Failure to scan our projects is an unfair disservice to our users. If we don’t find the vulnerabilities by scanning projects ourselves, attackers certainly will, because the Linux user base has increased to the point that Linux users are finally numerous enough to be worth targeting.

Content history (2)
  • 2026-10-04 · Summary · vi · Wording fix
    Con người thật sự kém cạnh khi viết mã an toàn, và các nhà phát triển GNOME cũng không ph…
    Con người viết mã an toàn rất kém, và các nhà phát triển GNOME cũng không phải ngoại lệ. …
  • 2026-10-04 · Title · vi · Wording fix
    Thời đại Chất lượng Phần mềm, hay Thời đại Những con Cú?
    Thời đại chất lượng phần mềm, hay thời đại những con đà điểu?
Sign in to suggest edits

Key sources

  1. DISCUSSIONcalvinlobste.rs
Markdown