Hacker News new | ask | show | jobs
by ziddoap 842 days ago
This post clears it up a bit more.

https://blog.jetbrains.com/teamcity/2024/03/our-approach-add...

And this is the part Rapid7 presumably took issue with.

>At this point, we made a decision not to make a coordinated disclosure with Rapid7

As well as

>We published a blog post about the release. This blog post intentionally didn’t mention the security issues in detail

Which is presumably the blog post that Rapid7 saw, which triggered their silent patching policy.

Although, after reading all the blog posts (from Jetrbrains, and from Rapid7), I think this is a much more standard affair than The Reg tries to spin in its article.