2 days ago
If you have found security vulnerabilities in a small project, then starting a public relations circus will actually slow down getting it fixed properlyBecause guess what? Small projects don’t have a dedicated PR team. The developers *are* the PR team. And every minute they spend trying to deal with the PR disaster you’ve created for them is a minute they’re not spending fixing the damn bug