Federal funding for Mitre and the CVE program is over. (Why the Government was giving Mitre $5 billion dollars for what amounts to simple CSV document and email chatbot is beyond my comprehension.)
I’m taking the opportunity to alter my position:
Disclosing vulnerabilities in secret to the government and giant corporations isn’t “responsible disclosure”.
Immediate public release of all findings is responsible disclosure.