On Thu, Jul 30, 2026 at 9:45 PM Alan Coopersmith <[email protected]> wrote: > > https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-security-tracking/ > announces some changes to the GNOME project's security bug handling: > > 1) The disclosure deadline is cut from 90 days to 30 days, as most > GNOME maintainers that fix bugs during the embargo do so within > the first 30 days. This is effective for new bugs reported starting > August 1. > > 2) The GNOME security team will no longer forward vulnerability reports > to projects that ban AI-generated content, since most reports they > get these days have at least some AI-generated content.
Is there a convenient list somewhere of what projects are in this category? Distributions may be wise to mark such applications as ineligible for security support, and end-users would probably do well to avoid using them to process untrusted data. -- Aaron > 3) Michael Catanzaro will be stepping down in November, after 6 years > of handling this work for GNOME. He's looking for someone to step > up to replace him. > > -- > -Alan Coopersmith- [email protected] > Oracle Solaris Engineering - https://blogs.oracle.com/solaris >
