GNOME Shortens Disclosure Due to AI-Generated Reports
Summary
GNOME is shortening its vulnerability disclosure window due to a rise in AI-generated security reports. Volunteer maintainers now receive many such reports, often without disclosure of AI use. Michael Catanzaro, who handles GNOME's security issue tracking, says that non-AI reports are becoming "moderately unusual." The project will now treat all vulnerability reports the same, regardless of AI involvement. GNOME will switch to a 30-day disclosure deadline for issues reported on or after August 1st, 2026. This is a change from the previous 90-day window, which often led to delays. Some GNOME projects ban AI-generated content in reports. For these, Catanzaro will stop forwarding security reports to their issue trackers, as most now contain AI-generated material. This change matters because it reflects how AI is impacting open-source project security and maintenance.
This is an AI-generated audio summary. Always check the original source for complete reporting.