@wolf480pl @phnt @sjvn @lanodan I think the public, in general, puts too much pressure on small, mostly volunteer teams.
On the one hand, these projects are vital lynchpins holding up trillion dollar industries.
On the other, they apparently aren't worth a contact or even a donation by those using them.
I imagine corporations would spend FTEs building complicated workarounds rather than fund an open source protect. They think, "someone else will step in and fix it, eventually."
What can the small projects do? I don't know. So much of our infrastructure is designed around taking away their power while magnifying their responsibility. If it were me, I'd probably work myself to death trying to be everything for everybody. Ideally, they'd be able to go on strike. No fixes the leeches step up with people or funds. But that's taking your life into your own hands. That could end badly.
I don't have a solution. The most important thing is to prioritize but with AI generated CVEs, I'm not sure the flood is manageable.
My advice is that your mental health should come first. Always. Every day. Take care of yourself.