The CVE thing gets sillier every month.
On one hand you have the laziness of Mitre and friends to add any silly CVE claim, unless someone like @bagder pushes back using days of his precious time
Otoh, there are these „super CVEs“ which apply to several projects and people demand coordinated rollouts on specific dates to limit exposure. But most projects don‘t work that way.
And I‘m not sure why unpaid people are putting in extra effort to protect business interests, myself included.