Your software has a security vulnerability which you fix and disclose: That happens, not a concern unless there’s a trend or other context.
Your software has a security vulnerability which you fix but never mention: Enormous red flag.
Your software has a security vulnerability and you make legal threats against whoever disclosed it: You should not be allowed to software, everything you’ve made should be uninstalled immediately.
