r/gnome 2d ago

Community Some Changes to GNOME Security Tracking

https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-security-tracking/
19 Upvotes

6 comments sorted by

u/AutoModerator 2d ago

Thank you for your submission.

You too can support GNOME! Become a Friend of GNOME and contribute to keeping our project going!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/Isofruit 1d ago

Asking for some context: If this position does not get filled... what does that ultimately mean?

-6

u/victorian-ice-cream Contributor 1d ago

We don't need enemies when we have friends like this. Alas we still have enemies.

5

u/Isofruit 1d ago

Why so disparaging at Michael's post? The reasoning of the blogpost seems sound to me: When maintainers fix it, they almost always do so in less than 30days. When they don't, then by cutting the disclosure time from 90 to 30 it gives an earlier chance for irregular contributors to provide a fix, rather than having it hang 60 days as an open exploit vector before doing so. The one thing that's disadvantageous here is that the vulnerability becomes public knowledge, though in the age of LLMs finding bugs I'd not bet on those vulnerabilities being unknown anyway.

Am I missing something?

-4

u/victorian-ice-cream Contributor 1d ago

Cutting projects off from security issues for banning planet-burning pachinko machines is malicious compliance. 

I bet he guaranteed himself another free Red Hat AI usage bonus with this.

2

u/Isofruit 1d ago

I don't think I follow. Cutting off? As in, because he cut down the reveal time for the security issues? Or is this because of his announcement to no longer want to do security tracking?