What professional standard applies when a Node.js developer discovers a security vulnerability in an open-source package they use?
-
A
Keep it private and exploit it for competitive advantage
-
B
Report it responsibly to the maintainer through the project's security disclosure process
-
C
Immediately post the vulnerability publicly on social media
-
D
Stop using Node.js entirely