http://tstzmgqansvqfzr3qrkehszmlhjqbpqp7pwncrzr72ohyygrnbuu26qd.onion/articles/libre-software-security-disclosure
This is why I think the best is to also gradually disclose information in the open, you can still notify distribution maintainers, but don't make it an in-group. For example if writing a patch takes time, you can publish a workaround ("A vulnerability in feature $X got reported, disable it"). It also means that when publishing the patch, you do not describe what vulnerability it fixes, make it more like a mere bug and link it to an identifier (CVE, bug-id, …).