Sort:  

Good idea -- except it is still public. Assume that I found an easy exploit (what I found was not -- but I still don't care to publicize it), how can I alert the developers without it being public?