Hacker News new | ask | show | jobs
by 001spartan 4460 days ago
I was under the impression that they did in fact contact package maintainers in addition to companies like CloudFlare.
1 comments

Nope; package maintainers said they didn't get notified, and OpenSSL explicitly has no notification mechanism for such things. CF found out because the private entities which found the bug warned them a priori with a request to not disclose it to anyone else. See also: https://news.ycombinator.com/item?id=7549986