I've discovered a serious flaw in a widely used open-source software that poses a security risk, but publicly disclosing it without a fix could expose millions to exploitation – do I disclose immediately for transparency or delay to develop a patch first?