On 7/30/26 23:41, Alan Coopersmith wrote:
https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome- security-tracking/
announces some changes to the GNOME project's security bug handling:

1) The disclosure deadline is cut from 90 days to 30 days, as most
    GNOME maintainers that fix bugs during the embargo do so within
    the first 30 days.  This is effective for new bugs reported starting
    August 1.

I hope that new approach won't be copied by other projects: I would
certainly not be amused about a 30 days deadline where it affects me, in
particular not with sometimes multiple cases coming in at nearly the same time. If most issues are resolved within a 30 days window in GNOME,
that's not saying that cutting down the window will work well for all
projects involved, and the post seems to lack a good rationale about it.


2) The GNOME security team will no longer forward vulnerability reports
    to projects that ban AI-generated content, since most reports they
    get these days have at least some AI-generated content.

For what it's worth, that kind of pre-filter does not seem healthy to
me and "a bit" too dogmatic.


3) Michael Catanzaro will be stepping down in November, after 6 years
    of handling this work for GNOME.  He's looking for someone to step
    up to replace him.

Thanks to Michael for having done this work for a so long!

Reply via email to