Definition

Process where security researchers report vulnerabilities to vendors privately, allowing time to patch before public disclosure — typically accompanied by CVE assignment, release notes, and user migration guidance.

Key Points

  • 2026-10-04: xray-core case study in disclosure failure — silent fix Feb 2026, incomplete fix until July 2026 advisory (2026-10-04-xray-core-cert-verification-bypass)
  • Best practice: security release notes, version matrix, CVE/GHSA ID, clear mitigation steps
  • “Simplify code” commit messages on security fixes prevent users from assessing exposure window
  • Turkish developers using proxy stacks (v2rayN, etc.) depend on maintainer transparency for trust

Sources