Catanzaro: Some changes to GNOME security tracking
Michael Catanzaro, who has been managing GNOME security issue tracking since November 2020, has written a blog post that details some changes in how he will be managing GNOME vulnerability reports from now on due to an increase in AI-generated security reports.
Intelligence analysis by Llama

Catanzaro will be switching from a 90-day deadline for disclosures to 30 days for issues reported on August 1, or later. He will also be stepping away from the task of managing security issue tracking entirely by December 1, 2026.
Imagine you're playing a game where you have to find and fix bugs. The game is getting harder because some people are making fake bug reports. To make it easier, the game is changing the rules so that you have to fix the bugs faster. Also, the person in charge of finding and fixing the bugs is leaving, so someone new needs to take over.
Analysis
A Shift in Security Tracking Deadlines
Michael Catanzaro, the current manager of GNOME security issue tracking, has announced changes to the way he will be handling vulnerability reports. The primary reason for this shift is the increasing number of AI-generated security reports. Catanzaro believes that a 30-day deadline for disclosures would be more suitable for GNOME, even without the rise in AI-generated issue reports. This change will take effect on August 1, or later, for issues reported after that date.
The Future of Security Tracking
Catanzaro has also indicated that he will be stepping away from the task of managing security issue tracking entirely by December 1, 2026. This means that there will be a gap to fill in the management of security issues. Currently, nobody else is tracking GNOME security issues. Catanzaro has expressed interest in finding someone to take over this work and has encouraged experienced GNOME community members to come forward. He has also suggested that this may be an opportunity to improve the tracking infrastructure, potentially replacing the current wiki page with a more dynamic web app.
The Road Ahead
The changes announced by Catanzaro will have a significant impact on how GNOME handles security issue tracking. The shift to a 30-day deadline and the potential gap in management may lead to a more complex and challenging environment for security issue tracking. However, this may also present an opportunity for improvement and innovation in the way GNOME handles security issues.
Key points
- Michael Catanzaro is changing the deadline for GNOME security issue tracking from 90 days to 30 days.
- Catanzaro will be stepping away from managing security issue tracking by December 1, 2026.
- GNOME needs to find a replacement for Catanzaro to manage security issue tracking.
If GNOME can find a suitable replacement for Catanzaro and improve their tracking infrastructure, they may be able to handle security issues more efficiently and effectively.
The gap in security issue tracking management may lead to a more complex and challenging environment, potentially resulting in delayed or missed security fixes.
