[PATCH 0/5] docs: improve guidance for AI-assisted bug reports

From: Willy Tarreau

Date: Sun Aug 02 2026 - 16:36:21 EST


While vulnerability reporters have now started CCing maintainers,
showing they read the docs, the security team still spends a lot of
time repeating the same comments about tested version, incomplete
fixes, poor email client setup causing formatting issues making
patches unusable, unverified reports and missing Assisted-By tags,
each time for AI-assisted reports.

This series adds small updates to security-bugs.rst, threat-model.rst
and coding-assistant.rst to better deal with this and provide minimal
instructions helping the LLM follow our expectations.

The updates were iteratively and carefully tested with 3 models,
Opus-5, Qwen3.6-27B-Architect-Polaris2-Fable-B-F451, and Gemini,
until all of them strictly followed the rules.

It is expected to further improve the situation.

Willy Tarreau (5):
docs: threat-model: clarify "security bug" vs "vulnerability"
docs: threat-model: move fake devices out of "non production use"
docs: security-bugs: clarify what counts as a valid version
docs: coding-assistant: explain important steps when looking for bugs
docs: security-bugs: clarify some mandatory steps for AI reports

Documentation/process/coding-assistants.rst | 37 +++++++++++++++++++
Documentation/process/security-bugs.rst | 26 ++++++++++++++
Documentation/process/threat-model.rst | 39 ++++++++++++---------
3 files changed, 85 insertions(+), 17 deletions(-)

--
2.52.0