The lead developer of the Libxml2 library has announced that all vulnerability reports submitted to the project will be public by default

Nick Wellnhofer says security flaws will also no longer have a deadline to release a fix, and they'll be patched when he has time

Wellnhofer hopes the new policy will make downstream users nervous and encourage them to contribute back to the project

The Libxml2 library is currently used in macOS, Windows, and operating systems
gitlab.gnome.org/GNOME/libxml2

0

If you have a fediverse account, you can quote this note from your own instance. Search https://social.data.coop/users/cryptohagen/statuses/114742483693300289 on your instance and quote it. (Note that quoting is not supported in Mastodon.)