DEV Community

Discussion on: I reported a security vulnerability. Now what?

Collapse
 
michaelgv profile image
Mike

There’s a limit of responsible disclosure, I usually do 90 days after report. Make sure you do numerous follow ups if they fail to respond and inform them you’ll be disclosing in 90 days if they fail to provide a patch.

If they disagree it’s a vulnerability, then let the internet decide in your public disclosure.