Michael Catanzaro is stepping away from managing GNOME’s security issue tracking, a role he has held largely by himself since November 2020, with support from Red Hat. He calls the work mostly administrative, following each report from the moment it lands to whenever it gets fixed or the clock runs out, and requesting a CVE once that happens.
Come November 1, 2026, Michael will stop tracking newly reported security issues, only focusing on issues that were already in the pipeline before that date. By December 1, he anticipates that every disclosure deadline tied to that remaining batch will have passed, and his part in handling issues will be done.
Alongside that, he is also changing how GNOME handles vulnerability reports overall. Pointing to the rise of AI-generated security submissions, he says that for issues reported on or after August 1, 2026, the disclosure deadline is now just 30 days, a 60-day drop from 90.
And projects that ban AI-generated contributions have to take note. Any security issues submitted to GNOME Security won’t be forwarded to such projects, given how much of what comes in today carries AI involvement. Michael will instead close the report in GNOME Security’s own tracker and reach out to the project’s maintainers directly to flag that it exists.
Someone needs to step up
Michael is currently looking for someone to take the role over, but not just anyone. He wants an experienced member of the GNOME community, someone who already knows their way around the project, to step in.
He’s offered to help whoever takes it on get started, but is clear that this isn’t a good task for newcomers.
Whoever takes over would inherit the workflow that runs through a form on security.gnome.org, which funnels submissions to a security team that aims to acknowledge new reports within two business days.
Whatever gets submitted through that form is used to open a confidential issue on GitLab, which is then assigned to the relevant project maintainer as the primary handler.

They would also need to take over the archaic way of keeping track of all the security issues for GNOME, which is a basic wiki page on GNOME’s GitLab instance. It has to be updated manually, with every new report, fix, and disclosure going into separate tables split by year and project.
Other Linux projects already run something closer to that. Ubuntu publishes searchable, filterable security notices tied to CVE IDs. Fedora and Red Hat route tracking through Bugzilla instead, where a parent bug logs the underlying flaw, with separate tracking bugs filed against each affected package.
You can go through Michael’s announcement for more information.
![]()
This article first appeared on Read More