Catanzaro: Some changes to GNOME security tracking

Post Syndicated from jzb original https://lwn.net/Articles/1083754/

Michael Catanzaro, who has been managing GNOME security issue tracking since
November 2020, has written a blog post that details some changes in how he will
be managing GNOME vulnerability reports from now on due to an increase in
AI-generated security reports. He will be switching from a 90-day deadline for
disclosures to 30 days for issues reported on August 1, or later. “The
shorter deadline would probably work better for GNOME even if not for the
increase in AI-generated issue reports.

He also has indicated that he will be stepping away from the task of managing
security issue tracking entirely by December 1, 2026, which means that there
will be a gap to fill:

Currently nobody else is tracking GNOME security issues. If you are an
experienced GNOME community member and you are interested in taking over this
work, let me know and I will help you get started. (Security tracking is not a
good task for newcomers.)

This may also be an opportunity to improve our tracking infrastructure. I use
a wiki
page
, but this is fairly primitive and requires considerable manual
upkeep. It’s easy to forget to update the page when an issue report is closed,
for example. Ideally, we would replace the wiki with a proper web app that
dynamically updates based on the actual state of the issue.