Fediverse developer, when someone reports a security issue with your software, there is one and only one correct course of action.
Say thank you. Prioritize an immediate fix. Publish a hot patch version for all applicable major versions within hours or days. Publicly acknowledge the report.
Avoid minimisation, whataboutism, personal attacks, and complaining about the work involved.
@evan Typically you have to pay for things like QA, user research, security audits, etc.
And most people don't even bother telling you when they encounter issues with your website or app, they just move on.
People really need to learn to be humble and appreciate when a stranger takes the time out of their day just to help them improve their work.