I was referring to compute and data, local AI is still crap mostly, unless you have a rack of NVIDIA GPUs; I can run some big local models on 256gb of RAM, but they are too slow for my liking. Besides, models today are at 1-3 trillion parameters, not even the 1.5tb Mac Studio would run those. Local AI can be helpful but it’s more like pre-November mainstream agentic AI IMO. Unless you have an extremely sensitive application, then you need local/on-premises, and probably should have the budget for your own AI infra then.
I believe the outcome will always depend heavily on how these tools are used. In my view, discovering vulnerabilities often takes more time than fixing them. Attacking a framework requires analyzing many different components and scenarios; once an issue has been identified and understood, the appropriate fix is often much clearer.
An LLM may not always be able to implement the right fix on its own, but an experienced human can guide the implementation, review the changes, and validate the result.
We have already automated much of this process with AI. Today, the full release process takes about an hour to complete. That is a significant improvement, although there is still plenty of room to make it faster and more reliable.
This is something I would really like to see in Meteor someday. It would undoubtedly require a major effort, but with the newest models, it may be easier than we imagine and perhaps possible to achieve gradually without introducing breaking changes.
I believe this is a direction many people in the community would welcome. However, to be transparent, it is not our highest priority right now, as we are already stretched thin delivering the current roadmap.
I encourage you to continue the discussion in this forum thread. I would be happy to help coordinate a community-led initiative exploring this direction. However, given our current priorities, the initiative would need to be driven primarily by the community.