@nprofile1q... I don't fully understand your line of questions. Project Lightwell isn't just "we find vulnerabilities and report them placing burden on the project" it's "we find them, fix them, and contribute them upstream in a responsible manner" (embargos and such). The value prop for customers is we will also backport those fixes to whatever version of the software (and its dependency chain) that the customer wants/needs. If those versions are still maintained upstream, we'll contribute to those too.