> I'll just be blunt, I find this very hard to believe.
Email was the primary contact mechanism listed in the SECURITY.md file on GitHub. On your GitHub profile, you have listed links to socials (Mastodon/Bluesky/Twitter), your e-mail address, your personal website, and a video game website.
Messaging or tagging you there about an unpatched RCE would have effectively been a public zero-day disclosure, which we strictly wanted to avoid.
> Did you instruct other people not to use it within rocks.nvim?
That, too, would have been a public disclosure. All we knew at the time was that there appeared to be a second security researcher testing your site. In such situations, when there exists no perfect way to handle things, it's better not to "drop everything and panic", and to attempt *private* outreach via *defined* channels.
> statements like that make it hard for me to give you the benefit of the doubt regarding your attempts to contact me.
Rather than going back and forth on motives, how about we focus on establishing a clearer direct line of communication for the future?
> specifically the actual exploitation on the production server
Since I did not conduct the research myself, I am not in a position to comment on the technical details of it.