r/gnome • u/The_Hubster • 17h ago
Platform The man who kept GNOME secure is stepping down
THIS IS A BIG BIG DEAL.
Saw this from It's FOSS:
For six years, one person has been manually tracking every security vulnerability reported to GNOME. That person is leaving.
Michael Catanzaro has been GNOME's sole security coordinator since November 2020. No team. No automated system. Just one person triaging every report that comes in.
He's stepping down by December 2026.
And it gets more complicated. AI-generated vulnerability reports are now flooding his tracker. Low-quality, algorithmically-written submissions that look real enough to take seriously but rarely lead anywhere.
So before he leaves, he's changing the rules. Starting August 1, the coordinated disclosure window drops from 90 days to 30. AI-suspected reports will be closed without forwarding to maintainers.
Here's the part that surprised me: GNOME still tracks all of this on a wiki page. Not a proper bug tracker. Not searchable notices like Ubuntu or Fedora use. A wiki.
One person, a wiki, and a deadline shrinking by two-thirds.
More details at MIchael's official blog here:
https://blogs.gnome.org/mcatanzaro/2026/07/20/some-changes-to-gnome-security-tracking/




