Damus
Anil Madhavapeddy · 5w
I've had to respond to multiple OSS security issues recently and the wild thing is that agents can now generate exploits just on the *rumour* of a bug. This throws security embargoes out the window, a...
Edwin Török profile picture
@nprofile1q... I think that when the title, or CWE of a vulnerability and a package name is publicly known it should be assumed that the actual vulnerability is easily rediscoverable.
Maybe at that point the security advisory should already be published (referencing a git commit/branch/PR even if not a full release yet). Delaying the release of the details puts defenders at a disadvantage, with only minimal impact on attackers (which can rediscover those details with other tools).