[20:58:50] Anybody has a clue what the MediaWiki social media accounts are for if they don't communicate on an Extension vulnerability that got many instances pwned? 😜 (talking about the mastodon one, I don't know what they are posting elsewhere, but I doubt it's different?)? I have been trying to reach out, posted here https://piaille.fr/@maxlath/117359165825147992 and sent [20:58:50] an email to [20:58:51] the vulnerable instances I could find, but feel quite alone in the effort. It can't be enough to just assume admin sys will eventually read the mailing list and learn about it. [21:05:28] Theres a few volunteers who run it. But we have other channels that communicate about security problems and releases. (re @maxlath: Anybody has a clue what the MediaWiki social media accounts are for if they don't communicate on an Extension vulnerability that...) [21:49:13] that said, they did not communicate about this one either. There was an email to mediawiki-l but not mediawiki-announce. I feel there is a disappointing lack of planning & procedures around situations like this, and a rather large disconnect between wikimedia security and the broader mediawiki ecosystem (re @djhartman: Theres a few volunteers who run it. But we have [21:49:13] other channel [21:49:13] s that communicate about security problems and releases.)