Hacker News new | ask | show | jobs
by jwilk 3437 days ago
I don't believe the workflow has changed. CVE for public security issues in free software should be requested on oss-security.

And even if you don't care about the CVE business, posting to oss-sec about your bugs is the right thing to do.