GNOME's security team changed its vulnerability-handling process by cutting the default disclosure deadline for new reports from 90 days to 30 days and by declining to forward reports to projects that prohibit AI-generated submissions. The policy shift, discussed widely on the oss-sec mailing list, reflects the view that most embargoed fixes are completed within the first month and that AI-assisted reporting has become common enough that many submissions now contain at least some machine-generated material. Participants also noted that some projects, including the Linux kernel, have moved away from embargoes for AI-generated reports because such findings can be easily reproduced and redistributed.
The change triggered a broader dispute over open-source security governance, with maintainers arguing that low-quality, verbose, or impractical AI-assisted reports are consuming scarce triage capacity and pushing burnout onto already overstretched teams. Mailing-list contributors said many externally submitted bugs are real defects but not necessarily exploitable vulnerabilities, while others warned that rejecting accurate reports could still increase user risk. The debate expanded to the Linux Foundation's Akrites initiative, described by critics as an attempt to coordinate AI-era vulnerability response and potentially serve as a "maintainer of last resort" for abandoned critical packages, though others stressed that such a role would not override project ownership or maintainer authority.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On August 3, 2026, Emily Shepherd referenced a Linux Foundation announcement stating that Akrites would act as a maintainer of last resort only for critical packages with no active maintainer, and that fixes should flow back on maintainers' terms. She argued this did not override project licenses, naming rights, or maintainer authority.
On August 3, 2026, Yves-Alexis Perez asked for a reference supporting claims that the Linux Foundation's Akrites initiative would coordinate security incident response and act as a 'maintainer of last resort.' His message highlighted that the thread had not yet substantiated those assertions.
GNOME stated that the new 30-day disclosure deadline would apply to new vulnerability reports starting August 1, 2026. This was presented as part of the July 20, 2026 policy change announcement.
In a July 20, 2026 blog post, GNOME announced changes to its security bug handling process. The changes included shortening its disclosure deadline for security bugs from 90 days to 30 days.
A pkgconf policy cited in the oss-sec thread asserted maintainer autonomy over disclosure schedules, embargoes, confidentiality demands, and machine-generated submissions. The policy also warned that organizations disrespecting maintainer autonomy could face an organization-wide ban.
In the oss-sec discussion, Alan Coopersmith said the GNOME security team would no longer forward vulnerability reports to projects that ban AI-generated content because most reports now contain at least some AI-generated material. Participants said Michael Catanzaro was honoring those projects' requests by not sending such reports onward.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceheronsperch.blogspot.com
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcemetr.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.