TootSweet@lemmy.world 8 hours ago
If you have to ask the question, just take the secret to your grave. You should only risk the blowback on yourself if you know how properly to mitigate the risk of “doing the right thing”.
And maybe it’s fine. Like, if you found a vulnerability in a piece of FOSS software, most projects have an official path for disclosure of such things. Just look on their website and follow the instructions there. But if anyone asked me this question specifically about a vulnerability in some FOSS software, a) I’d say they don’t have the knowledge to make an informed decision whether it’s safe for them to do so and b) I’d question whether they’d actually found what they thought they’d found.