Drivels on OSS security about CVEs