The Era of Software Quality, or the Era of Ostriches? — Michael Catanzaro
Michael Catanzaro has spent years handling GNOME security reports. His argument is blunt: AI-assisted vulnerability discovery is now useful enough that projects should judge reports by their evidence, not ban them because a model helped write them. But his own account is also a case study in what happens when finding bugs becomes cheaper than handling them. GNOME’s bounty program received 298 reports and accepted 71 before it closed in February 2026. It paid €183,900, but the influx overwhelmed the people reviewing reports, even with professional triagers. Catanzaro says bounty submissions were far noisier than unpaid reports. Meanwhile a Red Hat-commissioned GLib scan initially flagged 118 vulnerabilities; some findings were duplicates, and 46 were real bugs but not security vulnerabilities because they involved trusted typelibs. The validation work is not finished, so 118 is not a confirmed vulnerability count. ...