Post #3832384
2026-07-14 17:25 UTC
IMO the ability of OSS teams to handle AI generated security reports has been overwhelmed: too much backlog, not just those immediate reject slop reports, but genuine serious ones and real-but-just-bug ones
Reporters have utterly unrealistic expectations that projects have "security teams" waiting idly for reports and grateful for them. Reality: the day job, their own PRs, the reviews, the commitments.
security researchers: if you can get claude or copilot to fund a vulnerability in some code, get it to write the patch too, with tests. You might learn more about the software, or at least about building, testing and PR submissions.
It'll give you different legitimacy in the community as you move from "AI slop CVE spammer" to "contributor of patches of security holes"
#oss #cybersecurity #ai
Replies (0)
No replies.