GNOME Changes Security Disclosure Policies Due To AI-Generated Reports The GNOME project is reducing its security disclosure window from 90 days to 30 days starting next month due to an influx of AI/LLM-generated security reports, according to Red Hat's Michael Catanzaro, who leads GNOME security work. Additionally, security issues from projects that prohibit AI-generated content will no longer be forwarded and will be immediately closed. Catanzaro, who has tracked GNOME security issues since 2020, announced he will leave his role in December and is seeking a successor. GNOME Changes Security Disclosure Policies Due To AI-Generated Reports The GNOME project is changing its handling of security reports due to the influx of AI/LLM-generated security findings. First and most notably, beginning next month GNOME will be moving to a 30 day disclosure window rather than the industry 90 day period. Due to most GNOME security issues being fixed within the first one to three weeks or not fixed at all, Red Hat's Michael Catanzaro who currently leads the GNOME security work is planning to reduce the 90 day disclosure deadline to just 30 days for all future security reports. Another change being made is that for projects that prohibit AI-generated content, security issues will no longer be forwarded to them. Due to many security reports these days containing AI/LLM-generated findings and in turn violate individual project policies around no AI contributions, the issues will be just immediately closed instead in the tracker. Project maintainers will be pinged if they want to be aware at least of the findings. While working on GNOME security issue tracking since 2020 while at Red Hat, Michael Catanzaro announced he's going to be leaving his security tracking duties. Due to getting tired of it, he will discontinue tracking newly-reported security issues beginning in November. By December, all disclosure deadlines for those issues will be reached and he'll consider his role complete. Thus he's looking for experienced GNOME community member s to take over. More details on these GNOME security changes via First and most notably, beginning next month GNOME will be moving to a 30 day disclosure window rather than the industry 90 day period. Due to most GNOME security issues being fixed within the first one to three weeks or not fixed at all, Red Hat's Michael Catanzaro who currently leads the GNOME security work is planning to reduce the 90 day disclosure deadline to just 30 days for all future security reports. Another change being made is that for projects that prohibit AI-generated content, security issues will no longer be forwarded to them. Due to many security reports these days containing AI/LLM-generated findings and in turn violate individual project policies around no AI contributions, the issues will be just immediately closed instead in the tracker. Project maintainers will be pinged if they want to be aware at least of the findings. While working on GNOME security issue tracking since 2020 while at Red Hat, Michael Catanzaro announced he's going to be leaving his security tracking duties. Due to getting tired of it, he will discontinue tracking newly-reported security issues beginning in November. By December, all disclosure deadlines for those issues will be reached and he'll consider his role complete. Thus he's looking for experienced GNOME community member s to take over. More details on these GNOME security changes via