Michael Catanzaro, in charge of monitoring security issues in the GNOME project since 2020, has announced a reduction in the vulnerability disclosure period from 90 to 30 days. The decision to make vulnerability information public 30 days after receipt of the report is seen as a reasonable compromise, as maintainers typically address the issue within 1-3 weeks or ignore it altogether. The new policy will be effective on August 1, in response to a surge in vulnerability reports generated by AI assistants.
To streamline the management of vulnerability reports in GNOME, the distinction between manually created reports and AI-generated reports has been eliminated. This shift is due to the predominance of AI-generated reports, making it challenging to differentiate between the two categories accurately in many cases. However, reports explicitly identified as AI-generated will not be forwarded to GNOME subprojects with policies against processing AI-generated content. Such reports will be promptly closed, with notifications sent to the respective maintainers.
Furthermore, Michael, the sole developer responsible for identifying and coordinating patches for vulnerabilities in GNOME, has disclosed his intention to step down from his position on December 1, 2026. Consequently, the GNOME community is seeking a volunteer to fill his role. Failure to secure a replacement by November 1, 2026, will result in Michael ceasing to accept new vulnerability reports, with all existing reports required to be closed by December 1.