@bagder This is great news, but how much extra work and attention do these bug reports submitted as security reports give you, compared to having them as issues on GitHub? I see that most of the recent reports are non applicable as security reports, and while they may now all find real issues (of varying degrees), I assume security reports still take a higher priority and more attention for the team?
@Varpie yeah, the challenge is that they are suspected vulnerabilities which forces us to keep them secret while being assessed, and that is what makes them specially burdensome.