Replying to
I still find security vulnerabilities manually and sometimes a CVE gets assigned. This year I reported two security vulnerabilities in two different open source projects. One got assigned a CVE and was fixed. The other has as far as I know not been fixed.
I really don't care if the projects assign CVE numbers or not as long as the vulnerabilities get fixed.
