GNOME Changes Security Disclosure Policies Due to AI-Generated Reports
14 hours ago
- GNOME will implement a 30-day disclosure deadline for vulnerability reports starting August 1, 2026, instead of the previous 90-day standard, as the longer period is often unused by maintainers.
- If a project bans AI-generated content, vulnerability reports will no longer be forwarded to its issue tracker due to the prevalence of AI-generated reports; instead, maintainers will be notified directly.
- The author will discontinue tracking new security issues from November 1, 2026, and seeks an experienced GNOME community member to take over, suggesting improvements to the tracking infrastructure.