Hacker News new | ask | show | jobs
by hinkley 1 day ago
No, because we've already had documented cases of people socially engineering exploits into OSS projects.

See also https://wikipedia.org/wiki/Confused_deputy_problem

You don't need permission to publish an exploit, you just need someone or something else to do it for you.