Document the steps to report a vulnerability. 1. OSVDB: email moderators@osvdb.org and/or message @osvdb on GitHub or Twitter. 2. Request a CVE from oss-sec mailing list or reserve a CVE from MITRE. 3. Once OSVDB or CVE have been obtained, send advisory to `rubysec-announce@googlegroups.com`.