Other way around. Hi I'm the Kubernetes 1.14 release lead, I work for Google, and I'm the guy who said "bumpy road"
During the Kubernetes Contributor Summit at KubeCon Seattle last year, I made lots of noise about using KEPs, and about needing non-technical contributors to help those of us who are "organizationally challenged". In what I hope was a response, people showed up at SIG PM.
I think this conversation was really kicked back up in earnest as a result of Windows node support not landing in 1.13 due to a lack of clarity on what the bar was for release. There were other enhancements that could have had a smoother landings in this and previous releases, but this was definitely when we realized we needed to overhaul and document this part of the project.
tl;dr a fix is (edit: optionally) sent out to a private distributors list under embargo within 2 weeks of disclosure, and public disclosure (with new releases) happens within 3 weeks of disclosure (with some discretion for timing to make sure it's not buried in a weekend or off-hours)
I can't speak to who knew about it when outside of the project, but I know the project acted expediently once the vulnerability was disclosed.
It should be the artist's choice on how their work is released, but beyond that, they can do nothing.
Once an artist has released their work, the details of how it is consumed, how it is interpreted, and how it is used will always be well beyond their control.
Much like a startup must pivot, so too must an artist live in the world within which they create their work.
During the Kubernetes Contributor Summit at KubeCon Seattle last year, I made lots of noise about using KEPs, and about needing non-technical contributors to help those of us who are "organizationally challenged". In what I hope was a response, people showed up at SIG PM.
See https://youtu.be/_7IIzH_4yUk?t=998, https://youtu.be/mwG2CzdCg_8?t=1389, and https://youtu.be/mwG2CzdCg_8?t=1893 if you want to see me rambling about it on camera
I think this conversation was really kicked back up in earnest as a result of Windows node support not landing in 1.13 due to a lack of clarity on what the bar was for release. There were other enhancements that could have had a smoother landings in this and previous releases, but this was definitely when we realized we needed to overhaul and document this part of the project.