libxslt project maintainer steps down, citing the amount of time it takes to triage embargoed security issues.
“I’ve been doing this long enough to know that most of the secrecy around security issues is just theater. All the ‘best practices’ like OpenSSF Scorecards are just an attempt by big tech companies to guilt trip OSS maintainers and make them work for free.”