linkedin.com
GNOME Security Coordinator Steps Down, Changes Vulnerability Reporting Rules | It's FOSS posted on the topic | LinkedIn
For six years, one person has been manually tracking every security vulnerability reported to GNOME. That person is leaving.
Michael Catanzaro has been GNOME's sole security coordinator since November 2020.
No team. No automated system. Just one person triaging every report that comes in.
He's stepping down by December 2026.
And it gets more complicated. AI-generated vulnerability reports are now flooding his tracker. Low-quality, algorithmically-written submissions that look real enough to take seriously but rarely lead anywhere.
So before he leaves, he's changing the rules. Starting August 1, the coordinated disclosure window drops from 90 days to 30. AI-suspected reports will be closed without forwarding to maintainers.
Here's the part that surprised (read shocked) me: GNOME still tracks all of this on a wiki page. Not a proper bug tracker. Not searchable notices like Ubuntu or Fedora use. A wiki.
One person, a wiki, and a deadline shrinking by two-thirds.
GNOME needs someone experienced to step in. If you are part of the GNOME community or know someone who is, this is worth paying attention to.