A developer discovers a critical vulnerability in a public Docker image used by their organization. What is the most ethical course of action?
-
A
Delete the image from the registry immediately without notifying anyone
-
B
Report the vulnerability privately to the image maintainer before public disclosure
-
C
Post the vulnerability details on social media to warn the community
-
D
Ignore it since it is a third-party image and not their responsibility