GNOME's Security Might Be in Peril as Lone Tracker Goes Off

Michael Catanzaro has single-handedly run GNOME security tracking since 2020, but he is leaving in December.
Warp Terminal

Michael Catanzaro is stepping away from managing GNOME's security issue tracking, a role he has held largely by himself since November 2020, with support from Red Hat. He calls the work mostly administrative, following each report from the moment it lands to whenever it gets fixed or the clock runs out, and requesting a CVE once that happens.

Come November 1, 2026, Michael will stop tracking newly reported security issues, only focusing on issues that were already in the pipeline before that date. By December 1, he anticipates that every disclosure deadline tied to that remaining batch will have passed, and his part in handling issues will be done.

Alongside that, he is also changing how GNOME handles vulnerability reports overall. Pointing to the rise of AI-generated security submissions, he says that for issues reported on or after August 1, 2026, the disclosure deadline is now just 30 days, a 60-day drop from 90.

And projects that ban AI-generated contributions have to take note. Any security issues submitted to GNOME Security won't be forwarded to such projects, given how much of what comes in today carries AI involvement. Michael will instead close the report in GNOME Security's own tracker and reach out to the project's maintainers directly to flag that it exists.

Someone needs to step up

Michael is currently looking for someone to take the role over, but not just anyone. He wants an experienced member of the GNOME community, someone who already knows their way around the project, to step in.

He's offered to help whoever takes it on get started, but is clear that this isn't a good task for newcomers.

Whoever takes over would inherit the workflow that runs through a form on security.gnome.org, which funnels submissions to a security team that aims to acknowledge new reports within two business days.

Whatever gets submitted through that form is used to open a confidential issue on GitLab, which is then assigned to the relevant project maintainer as the primary handler.

a document titled home is shown here, which lays out the current security issues that are being tracked in gnome

They would also need to take over the archaic way of keeping track of all the security issues for GNOME, which is a basic wiki page on GNOME's GitLab instance. It has to be updated manually, with every new report, fix, and disclosure going into separate tables split by year and project.

Other Linux projects already run something closer to that. Ubuntu publishes searchable, filterable security notices tied to CVE IDs. Fedora and Red Hat route tracking through Bugzilla instead, where a parent bug logs the underlying flaw, with separate tracking bugs filed against each affected package.

You can go through Michael's announcement for more information.

Enjoyed this update? Support independent Linux news coverage

It's FOSS has been helping people use Linux for the past 14 years. Help us stay independent from big tech. Become a Plus member, enjoy ad-free reading and get 5 eBooks.

Plus yearly

Ad-free, FREE ebooks

Join yearly

Buy us a coffee

Any amount, no commitment

Support on Ko-fi
About the author
Sourav Rudra

Sourav Rudra

A nerd with a passion for open source software, custom PC builds, motorsports, and exploring the endless possibilities of this world.

Become a Better Linux User

With the FOSS Weekly Newsletter, you learn useful Linux tips, discover applications, explore new distros and stay updated with the latest from Linux world

itsfoss happy penguin

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to It's FOSS.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.