GNOME Shortens Security Disclosure Window Amid AI-Generated Reports
GNOME is reducing its vulnerability disclosure timeline from 90 to 30 days, citing the increasing volume of AI-generated security reports that often lack disclosure.

The GNOME project is implementing a significant change to its security vulnerability disclosure policy, shortening the confidential disclosure window from 90 days to 30 days. This adjustment, driven by Michael Catanzaro, who manages GNOME's security issue tracking, aims to streamline the handling of security reports in an era where artificial intelligence is increasingly used to generate them, often without explicit acknowledgment.
Catanzaro noted that volunteer maintainers are experiencing a surge in AI-generated vulnerability reports. A common issue is the lack of disclosure regarding the AI's involvement in crafting these reports. This trend has made it difficult to distinguish between human and machine-generated submissions, prompting GNOME to adopt a unified approach where all reports are treated equally, regardless of their origin. "Vulnerability reports that are not discovered by AI are becoming increasingly rare," Catanzaro stated, explaining the rationale behind optimizing for the new reality rather than the diminishing number of purely human-generated reports.
The previous 90-day confidentiality period, a common industry standard, often proved cumbersome for GNOME's workflow. Maintainers typically resolve valid reports within weeks, making the extended disclosure window redundant and sometimes leading to unnecessary delays. The new 30-day deadline is intended to strike a balance, allowing sufficient time for fixes while accelerating the public disclosure process. Catanzaro will request a CVE identifier once an issue is fixed or when the 30-day disclosure deadline is met, whichever occurs first.
This move contrasts with more aggressive approaches taken by other projects. For instance, the Linux kernel has adopted immediate disclosure for AI-generated reports, based on the premise that any vulnerability an AI can find is likely already known to adversaries. Catanzaro, however, views this as potentially too demanding for maintainers, risking rushed fixes. GNOME's 30-day window is designed to avoid such pressure while still improving efficiency.
Furthermore, GNOME is addressing the challenge posed by some individual projects within GNOME that have policies prohibiting AI-generated content in issue reports. Catanzaro plans to stop forwarding security reports to these project trackers if they contain AI-generated material, as most submissions now do. Instead, he will close the report in the central GNOME Security tracker and notify project maintainers. He encourages project maintainers to create specific exceptions in their AI policies for vulnerability reports if they wish to continue receiving submissions directly.
A technical hurdle identified is the current permissions structure within GNOME's security tracker. Maintainers lack access to confidential issues, and GitLab's system does not allow for CC'ing individual developers on confidential reports. Catanzaro has proposed widening permissions to grant all GNOME developers visibility into the security tracker, which could improve collaboration and transparency.
Catanzaro also announced his intention to step down from his role in security tracking by December 1, 2026, after more than five years. He describes the position as largely a "secretarial duty" that has become taxing. He plans to spend November clearing outstanding reports before his departure. Currently, no one else is formally assigned to track GNOME security issues, and Catanzaro is seeking an experienced community member to take over the role, ideally someone familiar with the project.
Looking ahead, Catanzaro sees an opportunity to upgrade the current tooling, which relies on a wiki page requiring constant manual updates and prone to synchronization issues. He envisions a dedicated web application that can accurately reflect the live status of each security issue, offering a more robust and efficient system for managing vulnerability disclosures within the GNOME ecosystem.