An empirical analysis of how leading open-source projects handle vulnerability disclosure through coordinated bug bounty programs, GitHub Security Advisories, and CVE assignment processes.
Oleh Ivchenko (Thu,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: