@sjvn I think it's unclear what's preventing ffmpeg devs from just ignoring these bug reports.
Like, if GPZ were to publish the details of an unfixed vuln in a rarely-used feature of ffmpeg, there shouldn't be much impact on real users, most of the pain would be with the CVE-obsessed corpos that use ffmpeg in their products, right?