On Thu, Jul 30, 2026 at 9:45 PM Alan Coopersmith
<[email protected]> wrote:
>
> https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-security-tracking/
> announces some changes to the GNOME project's security bug handling:
>
> 1) The disclosure deadline is cut from 90 days to 30 days, as most
>     GNOME maintainers that fix bugs during the embargo do so within
>     the first 30 days.  This is effective for new bugs reported starting
>     August 1.
>
> 2) The GNOME security team will no longer forward vulnerability reports
>     to projects that ban AI-generated content, since most reports they
>     get these days have at least some AI-generated content.

Is there a convenient list somewhere of what projects are in this
category? Distributions may be wise to mark such applications as
ineligible for security support, and end-users would probably do well
to avoid using them to process untrusted data.

--
Aaron

> 3) Michael Catanzaro will be stepping down in November, after 6 years
>     of handling this work for GNOME.  He's looking for someone to step
>     up to replace him.
>
> --
>          -Alan Coopersmith-                 [email protected]
>           Oracle Solaris Engineering - https://blogs.oracle.com/solaris
>

Reply via email to