It is our moral imperative to consider the "real world" and actual users when assessing the possible security impact of a reported issue. If we deem that there is likely to be zero affected users, then we do more damage than good by insisting on doing the security dance for the issue.

Then we end up with a severity level that is below LOW, and then we treat it as a bug instead. For the good of mankind.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/bagder/statuses/115892751895019304 on your instance and quote it. (Note that quoting is not supported in Mastodon.)