• wjs018@piefed.social
    link
    fedilink
    English
    arrow-up
    27
    ·
    1 month ago

    For those out there poking the code, please disclose responsibly! Don’t just make a public post about a security vulnerability, reach out to the devs first to give them a chance to create a fix.

  • julian@activitypub.space
    link
    fedilink
    arrow-up
    22
    ·
    1 month ago

    In a weird roundabout way a disclosure gives me more reassurance.

    If a software package went on for years and years without a peep with regard to security fixes or disclosures, I’d start to wonder what they’re hiding.