🛡 GNOME changes vulnerability disclosure rules due to AI reports
The GNOME project is shortening its standard vulnerability disclosure window from 90 to 30 days. This decision is driven by the fact that most issues are fixed within 1–3 weeks. Additionally, the project is introducing new rules for AI-generated reports: if a subproject prohibits the use of neural networks, such reports will be closed immediately in the tracker without being passed to developers.
🌍 This is an important precedent for the open-source community's reaction to the influx of automated content (AI-generated reports). The policy change aims to protect developer autonomy from low-quality AI spam.
👤 Vulnerability researchers and users of AI tools should note that major projects are beginning to implement neural network content filtering and accelerating bug fix cycles.
Source 1: https://www.phoronix.com/news/GNOME-Security-Changes-2026
