This normally takes a few days and a release within a week or two is reasonable. Within about ten minutes (!) this website was fielding probes for percent-encoded traversal sequences, indicating that automated watchers are keeping an eye on public repositories.
Anil Madhavapeddy, Just a rumour of a bug is enough to find a security exploit these days. Via Simon Willison.
the speed of n-day development has been independently validated enough times that it has to be accepted. i am also not sure exactly where we go. defense-in-depth is still our best bet. however, i think it will take a few high profile breaches before we face this. and it’s probably going to be in the next 6-12 months.
Pwn2Own Berlin hit maximum capacity for the first time in the contest’s history and closed submissions early. exploit production showed up as a scheduling constraint.
embargoes assume the details stay secret. at this point … a public PR, a mailing list hint, or a patch diff is easily enough search direction. scary stuff.