Hi all,
as anticipated in the previous two PSC meetings, here is a proposal to add an AI policy to GeoServer, that will hopefully propagate to GeoTools and GeoWebCache as well.
Compared to the version I presented during the meeting, I expanded the human communication section to target the AI slop, rather than explicitly banning AI in channels intended for human/human communication.
Cheers
Andrea
jive
July 17, 2026, 7:45pm
2
Thanks Andrea,
First of all +1
Second for the " Actions besides the policy itself" section:
Update CONTRIBUTING.md (even just to link to this policy)
Contributions made with AI assistance are your responsibility, and subject to project AI Policy.
Update Discourse user and developer category “before you post” instructions.
Forum is intended to support and encourage fellow humans, see project AI Policy.
Consider updating SECURITY.md to link to policy.
Not even sure what to say on this one …
I have tried adding a section to the GSIP specifically about security reports. I’m open to suggestions and improvements.
Cheers
Andrea
+1
Cheers,
Torben
On Fri, Jul 17, 2026 at 9:59 AM Andrea Aime <noreply@discourse.osgeo.org > wrote:
Someone replied to a topic you are Watching.
Hi all,
as anticipated in the previous two PSC meetings, here is a proposal to add an AI policy to GeoServer, that will hopefully propagate to GeoTools and GeoWebCache as well.
GitHub
Official GeoServer repository. Contribute to geoserver/geoserver development by creating an account on GitHub.
Compared to the version I presented during the meeting, I expanded the human communication section to target the AI slop, rather than explicitly banning AI in channels intended for human/human communication.
Cheers
Andrea
Visit Topic or reply to this email to respond.
You are receiving this because you enabled mailing list mode.
To unsubscribe from these emails, click here .
jive
July 29, 2026, 5:13pm
8
This motion has been open for ten days and has now passed.
jive
August 6, 2026, 6:16pm
9
Hi @aaime-geosolutions - I would like to propose a small clarification to SECURITY.md here:
main ← ai-disclosure-poicy-reminder
opened 06:12PM - 06 Aug 26 UTC
A large number of reports assume a vendor relationship, or link to a vendor secu… rity disclosure policy.
This clarification of SECURITY.md is to specifically remind users of AI tools that such an expectation is not appropriate.
# Checklist
- [x] I have read the [contribution guidelines](https://github.com/geoserver/geoserver/blob/main/CONTRIBUTING.md).
- [x] I have sent a [Contribution Licence Agreement](https://docs.geoserver.org/latest/en/developer/policies/committing.html) (not required for small changes, e.g., fixing typos in documentation).
- [x] I have read and applied the [AI policy](https://geoserver.org/ai)
- [x] First PR targets the `main` branch (backports managed later; ignore for branch specific issues).
For core and extension modules:
- [ ] New unit tests have been added covering the changes.
- [ ] [Documentation](https://github.com/geoserver/geoserver/tree/main/doc/en/user/source) has been updated (if change is visible to end users).
- [ ] The [REST API docs](https://github.com/geoserver/geoserver/tree/main/doc/en/api/1.0.0) have been updated (when changing configuration objects or the REST controllers).
- [ ] There is an issue in the [GeoServer Jira](https://osgeo-org.atlassian.net/browse/GEOS/summary) (except for changes that do not affect administrators or end users in any way).
- [ ] Commit message(s) must be in the form ``[GEOS-XYZWV] Title of the Jira ticket``.
- [ ] Bug fixes and small new features are presented as a single commit.
- [ ] Each commit has a single objective (if there are multiple commits, each has a separate JIRA ticket describing its goal).
The PR will be merged when all the build checks are green ([see automated QA checks](https://docs.geoserver.org/latest/en/developer/qa-guide/index.html)), there is a code committer review, and the checklist has been fulfilled.
I would like to discourage AI generated reports from assuming a vendor relationship.