http://tstzmgqansvqfzr3qrkehszmlhjqbpqp7pwncrzr72ohyygrnbuu26qd.onion/articles/libre-software-security-disclosure
("I want to use GnuPG to contact all distros" isn't a hill, it's a cliff, don't walk towards it.) This is why I think the best is to also gradually disclose information in the open, you can still notify distribution maintainers, but don't make it an in-group. For example if writing a patch takes time, you can publish a workaround ("A vulnerability in feature $X got reported, disable it").