The discussion
Most commenters land on rejecting the “zero hope without AI vulnerability scanning” claim as overstated, because they read GNOME’s own choice of C, C++ and Vala rather than the absence of AI as the source of the CVE wave. The sharpest objection is to the closing aside recommending against Rust for GNOME over Cargo: pyfisch, wrs and ghoti point out that cargo vendor, pinned versions and custom registries give GNOME full control of dependencies, so the real trade-off is vendoring discipline, not Rust versus trojanized crates. A second front is maintainer load: schneems and agent281 say AI reports destroy the effort signals maintainers used to triage contributors, while simonw and skyfaller argue over whether 100 dollars of tokens actually substitutes for a pentest team once subsidized token pricing is counted.