|
|
Message-ID: <CAFfBHfamJKqSx5XHzNDB7ozM_r9-nov85SfgOBxywNQC0c7SJg@mail.gmail.com> Date: Thu, 30 Jul 2026 21:58:03 -0500 From: Aaron Rainbolt <arraybolt3@...il.com> To: oss-security@...ts.openwall.com Subject: Re: Some Changes to GNOME Security Tracking On Thu, Jul 30, 2026 at 9:45 PM Alan Coopersmith <alan.coopersmith@...cle.com> wrote: > > https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-security-tracking/ > announces some changes to the GNOME project's security bug handling: > > 1) The disclosure deadline is cut from 90 days to 30 days, as most > GNOME maintainers that fix bugs during the embargo do so within > the first 30 days. This is effective for new bugs reported starting > August 1. > > 2) The GNOME security team will no longer forward vulnerability reports > to projects that ban AI-generated content, since most reports they > get these days have at least some AI-generated content. Is there a convenient list somewhere of what projects are in this category? Distributions may be wise to mark such applications as ineligible for security support, and end-users would probably do well to avoid using them to process untrusted data. -- Aaron > 3) Michael Catanzaro will be stepping down in November, after 6 years > of handling this work for GNOME. He's looking for someone to step > up to replace him. > > -- > -Alan Coopersmith- alan.coopersmith@...cle.com > Oracle Solaris Engineering - https://blogs.oracle.com/solaris >
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.