Do you have your process of how to handle bug reports written down? I'd love to see it, especially if it includes what data you gather, like the commit that introduced a bug.
I guess it's probably in everything curl or will be?
I guess it's probably in everything curl or will be?
Our process for handling security problems in curl is documented here: https://curl.se/dev/secprocess.html