Here's evidence to support that vulnerabilities should be publicly disclosed immediately.
This was posted on HN https://news.ycombinator.com/item?id=39866275 That guy did max damage. He did at least 750 commits to xz.

Here's evidence to support that vulnerabilities should be publicly disclosed immediately.