[email protected] re: "step up or shut up",
[email protected] has been (is currently?) a contributor for Pixelfed, and was the person responsible for the discovery, analysis, and responsible disclosure of the 10/10 severity vulnerability from last year.
She also provided best practice recommendations and guidance on remediation, all for free (there was no security fund back then, and Pixelfed has no bug bounty.)
For her to buck responsible disclosure practice (and even then she's being deliberately vague about the technical details) is a sign that someone is being stonewalled.