Hacker News new | ask | show | jobs
by dgellow 53 days ago
The author doesn’t owe forgejo anything. They are doing them a favor by highlighting the issues
1 comments

No, the author is seeking attention. He is not doing forgejo or their users any favours by completely ignoring the rules of engagement

https://en.wikipedia.org/wiki/Coordinated_vulnerability_disc...

coordinated disclosure has always been a courtesy (with a deadline to motivate the vendor to fix their stuff) and i don't like how people seem to just expect it now