Nice snark. Still, it was unnecessary: oddly, I do know what text editors
are.
However, the fact remains that editing the patch commit logs isn't done
unless necessary, and the stable tree maintainers don't think that
researching possible security implications, getting CVE info and so on is
a good use of their time. In the absence of their doing this, the only way
to enforce 'CVE info on everything' as you seem to want is the
development-speed-devastating scheme I outlined two messages up. Of
*course* this crazy scheme hasn't been adopted or even proposed, but that
is the only way to do what you suggest as long as the stable team's job
remains cherry-picking and applying patches that others write, rather than
actually modifying the commit logs, and the stable team have said that
this is what they consider their purpose to be.