What is the process for fixing a security bug?
• Work on the fix must proceed as quietly as possible, with discussion restricted to members of the security team. Code reviews will be performed as usual with the audience restricted to the security team. • Once a fix has been produced and tested, important users will be pre-notified. These users will be allowed to apply the patch before the bug becomes public knowledge. • The bug and the fix must be announced and made available simultaneously (or as close to simultaneous as possible).