Replying to
@pemensik@fosstodon.org @bagder@mastodon.social @dirkhh@hachyderm.io I have proposed fixes on some security reports to projects. One reason I'm leery of always doing so all the time is that a well written report can just as easily be fed by the receiver into their Claude to do the same work - but they'll have far more project context to guide it towards an acceptable result.
Remeber that for security reports, even before 2026, those are often filed against projects that reporters aren't already intimate with. We don't want to discourage reports of issues just because they don't include a fix.
At the same time, it is *always* fair for security report receivers to ask the reporter if they are able to write or generate any.