On Sun, Apr 20, 2014 at 1:42 PM, Richard Hansen [off-list ref] wrote:
I have discovered a minor security vulnerability. I could send the
patch to the mailing list, but I wanted someone else to take a look
first just to make sure it's minor enough that folks will think it's OK
to publicly announce.
Who should I send the patch to?
Previous issues were routed through the maintainer, Junio directly (CC'd).