freenode
Security & Cryptography

GNOME cuts vuln embargo to 30 days, stops AI-ban forwards

Longtime security coordinator Michael Catanzaro will step down in November and is seeking a successor.

GNOME is shortening its coordinated vulnerability disclosure window from 90 days to 30 days and will stop forwarding security reports to projects that ban AI-generated content, as longtime security coordinator Michael Catanzaro prepares to leave the role.

The tighter deadline applies to bugs reported from August 1. According to Catanzaro, most GNOME maintainers who fix issues during embargo already do so within the first month. Sebastian Pipping argued other projects should not adopt the shorter window, saying a 30-day limit would be unwelcome when several cases arrive together and that the change lacked a clear rationale beyond GNOME's own experience.

Separately, the GNOME security team will no longer pass vulnerability reports to upstreams that prohibit AI-generated material. Catanzaro cited the practical point that most reports now contain at least some AI-generated content. On the oss-security list, David A. Wheeler said Catanzaro was simply respecting those projects' stated wishes, yet called the outcome absurd: "Projects that reject truthful security reports are putting their users at risk." Aaron Rainbolt added that such projects leave a higher likelihood of unpatched flaws in the latest releases, and that distributions and users should treat them with caution for untrusted data.

Catanzaro will step down in November after six years of handling GNOME security tracking. He is looking for someone to take over the work.