A Rails developer discovers a critical security vulnerability in a gem used by a client's production app. What is the professional best practice?
-
A
Ignore it unless the client reports issues
-
B
Notify the client immediately and provide a remediation plan
-
C
Silently patch and deploy without telling anyone
-
D
Wait for the gem maintainer to release a fix first