http://tstzmgqansvqfzr3qrkehszmlhjqbpqp7pwncrzr72ohyygrnbuu26qd.onion/articles/libre-software-security-disclosure
It also means that when publishing the patch, you do not describe what vulnerability it fixes, make it more like a mere bug and link it to an identifier (CVE, bug-id, …). That said similarly to full disclosure I think information about flaws should be published in full, if only to benefit other researchers and implementers. But I think it should be done after a deadline (of say a month) rather than right away so everyone has the time to apply the fixes, forks included.