As with every software, eventually, someone may report a security issue as a public issue. In the event of a premature disclosure, we should have a contingency plan set up.
At @nodejs, this goes something along the lines of:
- Transfer the issue to a private repository
- Prepare and discuss a patch in the private repository
- Issue a security release via a push directly to the public repository