

If the bugs were being found in code that is used heavily in production I’d agree. Spamming the tracker with 100’s of bugs in random unmaintained areas of the code base just wastes everyone’s time. Perhaps as a project we should be more aggressive in deprecating code but the threat profile for someone running firmware blobs from their camera is very different from people launching untrusted guests on their shared hosting infrastructure.
Out of an abundance of caution we don’t let the tracker close bugs or assign CVEs but tell it to defer to a real human for that. I’ll have to experiment with how we can do a better job of detecting duplicates because I’m sure a fair number of the issues are.