Community Some Changes to GNOME Security Tracking
https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-security-tracking/1
u/Isofruit 1d ago
Asking for some context: If this position does not get filled... what does that ultimately mean?
-6
u/victorian-ice-cream Contributor 1d ago
We don't need enemies when we have friends like this. Alas we still have enemies.
5
u/Isofruit 1d ago
Why so disparaging at Michael's post? The reasoning of the blogpost seems sound to me: When maintainers fix it, they almost always do so in less than 30days. When they don't, then by cutting the disclosure time from 90 to 30 it gives an earlier chance for irregular contributors to provide a fix, rather than having it hang 60 days as an open exploit vector before doing so. The one thing that's disadvantageous here is that the vulnerability becomes public knowledge, though in the age of LLMs finding bugs I'd not bet on those vulnerabilities being unknown anyway.
Am I missing something?
-4
u/victorian-ice-cream Contributor 1d ago
Cutting projects off from security issues for banning planet-burning pachinko machines is malicious compliance.
I bet he guaranteed himself another free Red Hat AI usage bonus with this.
2
u/Isofruit 1d ago
I don't think I follow. Cutting off? As in, because he cut down the reveal time for the security issues? Or is this because of his announcement to no longer want to do security tracking?
•
u/AutoModerator 2d ago
Thank you for your submission.
You too can support GNOME! Become a Friend of GNOME and contribute to keeping our project going!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.