Article 773XH Catanzaro: Some changes to GNOME security tracking

Catanzaro: Some changes to GNOME security tracking

by
jzb
from LWN.net on (#773XH)

Michael Catanzaro, who has been managing GNOME security issue tracking sinceNovember 2020, has written a blog post that details some changes in how he willbe managing GNOME vulnerability reports from now on due to an increase inAI-generated security reports. He will be switching from a 90-day deadline fordisclosures to 30 days for issues reported on August1, or later. "Theshorter deadline would probably work better for GNOME even if not for theincrease in AI-generated issue reports."

He also has indicated that he will be stepping away from the task of managingsecurity issue tracking entirely by December 1, 2026, which means that therewill be a gap to fill:

Currently nobody else is tracking GNOME security issues. If you are anexperienced GNOME community member and you are interested in taking over thiswork, let me know and I will help you get started. (Security tracking is not agood task for newcomers.)

This may also be an opportunity to improve our tracking infrastructure. I usea wikipage, but this is fairly primitive and requires considerable manualupkeep. It's easy to forget to update the page when an issue report is closed,for example. Ideally, we would replace the wiki with a proper web app thatdynamically updates based on the actual state of the issue.

External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments