The GNOME Project is introducing new security rules, reducing the standard vulnerability disclosure window from 90 to 30 days and implementing filtering for AI-generated reports.
What Happened
The GNOME team has shortened the vulnerability disclosure window from 90 to 30 days, as most issues are fixed within 1–3 weeks. Additionally, the project is changing its approach to AI content: if a specific subproject prohibits the use of AI, reports generated by LLMs will be automatically closed in the tracker without being forwarded to developers.
Context
These changes are driven by the need to combat the growing volume of low-quality automated content (AI-generated reports). The rise in "noise" from AI-generated reports is forcing open-source communities to find ways to protect developer autonomy and optimize bug verification processes.
Why It Matters for the Industry
This sets an important precedent for the entire open-source industry, demonstrating how communities can react to the influx of automated spam. The policy change sets a trend toward increasing the value of verified human expertise and may lead to the formation of new standards for "quality" AI reporting, which would require technical proof (PoC) rather than just text.
Why It Matters for Users
Vulnerability researchers and developers using AI to find bugs should note that major projects are beginning to implement strict filtering of LLM content. This raises the barrier to entry for simple automated tools but accelerates overall fix cycles for critical errors.
What Is Not Yet Known / Limitations
There are various assessments of the consequences: ranging from purely technical process changes to the creation of significant barriers for solo developers and changes to global rules regarding how AI tools interact with infrastructure projects.
Sources
Author
Look at AI, Editorial Staff
