Posted Apr 4, 2008 22:36 UTC (Fri) by man_ls (subscriber, #15091)
[Link]
I don't think it counts as "hiding"; it is just "discreetly fixing before revealing"; other innocent parties can get hurt if this kind of information is disclosed. And after all the security team is not supposed to sit on security bugs indefinitely.
OpenSSH 5.0 released
Posted Apr 7, 2008 10:21 UTC (Mon) by jond (subscriber, #37669)
[Link]
To quote that part of the social contract in full:
"We will keep our entire bug report database open for public view at all times. Reports that
people file online will promptly become visible to others."