
Vulnerability Reports Are Not Special Anymore
Go maintainer Filippo Valsorda argues that large language models have removed the scarcity of security insight that once made confidential vulnerability reports special, moving the hard part of the job to triage.
For years, open source maintainers have been told to treat every issue, pull request and piece of feedback as a present rather than an obligation. Vulnerability reports were the exception: because a researcher who reports a flaw privately instead of publishing it is doing the project a favour, maintainers were expected to respond quickly, investigate, keep the reporter informed and credit the discovery.
Why the old rule existed
Writing on his blog on 23 June 2026, Filippo Valsorda — a long-time Go security maintainer, formerly lead of Google's Go security team and now part of the Geomys collective of professional Go maintainers — recalls explaining that distinction to new team members. The reason, he writes, was never that researchers themselves are special, but that the insight they brought and the temporary confidentiality around it were scarce, and projects needed both to ship a fix before attackers shipped an exploit.
That premise no longer holds, he argues. Large language models are now "as good as almost any security researcher", and everyone can run them: maintainers, but also attackers.
The bottleneck moved to triage
If anyone can generate a plausible list of bugs, the scarce resource is no longer discovery but judging which findings are real. Unless a trust relationship already exists, an outside researcher cannot meaningfully help with that triage, Valsorda writes, and reading through a model's output has roughly the same signal-to-noise ratio as reading a security@ inbox.
Confidentiality and embargoes lose much of their weight for the same reason: attackers do not need to read a full-disclosure post to learn about a vulnerability when they can ask their own model, and they probably face the same triage backlog as defenders. In a follow-up discussion he adds that he now triages well over a dozen reports a week, many of them genuine defects with an unclear impact on a typical user.
What maintainers are left with
Valsorda's conclusion is that triage, rapid remediation and prevention are now the core of the job, and that projects should look at running model-based analysis in CI. The post drew pushback as well as agreement: commenters argued that very severe reports and reports from highly trusted researchers will remain special, and that security teams may end up classifying reports quickly into those two buckets. Valsorda also notes the wider context — curl's month-long suspension of its vulnerability reporting channels — and admits that, as he wrote, he had no argument for servicing reports being the best use of time to protect users.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.