@drwhax I'm paid by Red Hat to do this, and am given access to all the resources I need -- but it must be soul destroying for an open source contributor just doing OSS for fun as a hobby.
I keep telling myself that all this security stuff isn't much fun, but it probably makes open source stronger in the long term.
I think it helps to have very strict rules upstream for the flood of AI reports, e.g. https://github.com/fwupd/fwupd/blob/main/SECURITY.md#reporting-a-vulnerability