For open source libraries, you are usually better off finding a large company that uses it in some exposed way, then submitting it to their bug bounty.
Sometimes you can even collect the bounty multiple times by sending it to multiple companies, so long as the first one doesn't submit the fix before the second even looks at the report...
Sometimes you can even collect the bounty multiple times by sending it to multiple companies, so long as the first one doesn't submit the fix before the second even looks at the report...