@GossiTheDog while they can certainly find some fun things, a number of the "vulns" are ridiculous "Oh this can be an RCE during full moons with ASLR disabled running on TRSDOS ported to ARM."
The models don't really threat model well at all. I like @bagder 's approach of VULN-DISCLOSURE-POLICY.md