Holden Karau writes in a personal capacity that AI has fundamentally changed the volume of security reports reaching open source projects, describing how Apache Spark’s 3.5.9, 4.0.4, and 4.1.3 patch releases were strained by roughly 30 security reports after initial filtering in the week before the first release candidate, only some of them actionable. She says an unnamed AI lab’s ‘Team X’ reported issues from at least February and set disclosure deadlines through a vendor rather than the broader maintainer group, that promised early access to a frontier security model produced only an August scan, and that late AI-driven bug fixes make fixed disclosure windows more likely to ship worse security bugs. She calls on frontier AI labs to give maintainers usable, non-time-limited access to their models, to be careful about using those models for security ahead of trusted-access programs, to show more flexibility on disclosure dates, and to fund and staff upstream maintenance, arguing reviewer bandwidth and maintainer burnout are the real bottlenecks.
Yet Another AI Security OSS Externality
Holden Karau writes in a personal capacity that AI has fundamentally changed the volume of security reports reaching open source projects, describing how Apache Spark's 3.5.9, 4.0.4, and 4.1.3 patch releases were strained by roughly 30 security reports after initial filtering in the week before the first release candidate, only some of them actionable. She says an unnamed AI lab's 'Team X' reported issues from at least February and set disclosure deadlines through a vendor rather than the broader maintainer group, that promised early access to a frontier security model produced only an August scan, and that late AI-driven bug fixes make fixed disclosure windows more likely to ship worse security bugs. She calls on frontier AI labs to give maintainers usable, non-time-limited access to their models, to be careful about using those models for security ahead of trusted-access programs, to show more flexibility on disclosure dates, and to fund and staff upstream maintenance, arguing reviewer bandwidth and maintainer burnout are the real bottlenecks.
Source: Holdenkarau