Michael Catanzaro has handled GNOME security reports since November 2020. Red Hat pays him for the work. Now he plans to stop. The volume of reports has grown. Many come from AI tools. The project responds with faster disclosure and new procedures. But the biggest shift may be the search for his replacement.
Shorter Timelines Meet a Wave of Automated Reports
Starting August 1, 2026, GNOME will apply a 30-day disclosure deadline to security issues reported on or after that date. The old 90-day window, long an industry standard, no longer fits. Most fixes arrive in one to three weeks. Or they never arrive. In either case the report becomes public once fixed or once the deadline passes. A CVE follows. “The 90-day deadline is intended to allow project contributors time to fix the issue before it becomes public, but in practice, maintainers do not actually make use of most of this time,” Catanzaro wrote in his July 20, 2026 blog post (GNOME Blogs).
The change applies across the board. No distinction between human and machine-generated reports. Reporters seldom admit to using AI. Non-AI reports have grown rare. Treating every submission the same simplifies the process. It also avoids the extreme step taken by the Linux kernel, which sometimes uses immediate full disclosure for suspected AI reports. That approach, Catanzaro noted, “seems pretty extreme, and is certainly unkind to maintainers who might feel pressured to urgently fix the issue.”
Phoronix first broke the news to a wide audience the same day (Phoronix). Linuxiac followed with its own summary, underscoring that the shorter window lets earlier disclosure occur when fixes land quickly (Linuxiac).
For projects that ban AI-generated content in their issue trackers the new rules go further. GNOME will no longer forward most reports. The majority now contain AI output and would violate those policies. Instead the security tracker closes the issue at once and pings the relevant maintainers so they know a report exists. Catanzaro had earlier urged projects to carve out exceptions for vulnerability reports. Few appear to have done so.
GitLab adds its own complications. Confidential issues in the GNOME Security tracker remain invisible to most GNOME developers. The system does not easily let individual maintainers be CC’d. Expanding permissions could help. Catanzaro invited opinions on that point.
These adjustments arrive alongside broader security gains in the desktop itself. GNOME 50, released earlier in 2026, made Wayland the only option. It removed the last X11 session code. The move ends a long migration. X11 let any application read input or inspect other windows. Wayland blocks that. The release notes also highlight new Kerberos authentication for remote desktop and headless servers, more reliable systemd-based headless sessions, and parental controls that lock screens at bedtime or after time limits. Foundations for web filtering without curated lists or broken security models sit ready for future work (GNOME Release Notes).
Yet policy and infrastructure matter as much as code. The security wiki that Catanzaro maintains demands constant manual updates. Forgetting to mark an issue closed happens too easily. He suggested a proper web application that pulls live data from the tracker. Such a tool could ease the burden on whoever follows him.
Catanzaro sounds weary but not bitter. “Security tracking is largely a secretarial duty: I keep track of issues when they are reported and when they are closed, disclose them when the deadline is reached, and request CVEs when appropriate. It is not a huge amount of work, but I am getting tired of it, so it’s time for a change.” He will handle only pre-November reports during that month. By December 1, 2026 every deadline will have passed. The role ends.
He seeks experienced GNOME contributors willing to step in. The work needs familiarity with the community, the tools, and the delicate balance between confidentiality and timely disclosure. No obvious successor had emerged in the first days after the announcement. Discussions on X showed appreciation for his service but also concern about continuity. One post called the situation “Huge kudos to Michael Catanzaro for all his work on this” while noting that “Currently nobody else is tracking GNOME security issues.”
The timing feels significant. AI tools now generate vulnerability reports at scale. Some contain real findings. Others waste time. Distinguishing them grows harder. GNOME chose not to fight the tide with extra rules. It shortened the clock instead. Thirty days still gives breathing room for quick fixes. It also pushes public awareness sooner when fixes stall. Attackers, after all, may already know what an AI can find.
GNOME 50’s technical security improvements provide a stronger foundation. Wayland’s isolation, Kerberos support, hardened remote sessions. These changes matter for daily users and administrators alike. But without steady oversight of incoming reports, even strong code can leave gaps. The next months will test whether the community can sustain the security tracking function that Catanzaro carried for nearly six years.
So far the conversation stays measured. No panic. Recognition that the old 90-day model had become mostly theater for this project. Acceptance that AI reports have changed the game. And quiet hope that someone steps forward before December. The desktop environment millions rely on depends on it.


WebProNews is an iEntry Publication