@somereatardedwood @bignose @libreoffice @TheASF it’s unfortunate but this is the case. Elsewhere in this thread I’ve posted at least three situations where a security researcher did proper bug filing against OOo, and then no release was done until after the security researcher had done the correct thing (waited, waited, and only then with reluctance published the vulnerability). And given that Libreoffice is doing regular security releases from a similar codebase, there’s almost certainly more.