What if maintainers for OSS projects said: "If you want security patches in a timely fashion, you **must** pay a subscription. Otherwise, we will just disclose the issue, then make the patch public in ~30 days". You would all lose your minds, but it also points out you *expect* work for free.
add a skeleton here at some point
27 days ago