On 7/30/26 23:41, Alan Coopersmith wrote:
https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-
security-tracking/
announces some changes to the GNOME project's security bug handling:
1) The disclosure deadline is cut from 90 days to 30 days, as most
GNOME maintainers that fix bugs during the embargo do so within
the first 30 days. This is effective for new bugs reported starting
August 1.
I hope that new approach won't be copied by other projects: I would
certainly not be amused about a 30 days deadline where it affects me, in
particular not with sometimes multiple cases coming in at nearly the
same time. If most issues are resolved within a 30 days window in GNOME,
that's not saying that cutting down the window will work well for all
projects involved, and the post seems to lack a good rationale about it.
2) The GNOME security team will no longer forward vulnerability reports
to projects that ban AI-generated content, since most reports they
get these days have at least some AI-generated content.
For what it's worth, that kind of pre-filter does not seem healthy to
me and "a bit" too dogmatic.
3) Michael Catanzaro will be stepping down in November, after 6 years
of handling this work for GNOME. He's looking for someone to step
up to replace him.
Thanks to Michael for having done this work for a so long!