The drumbeat here has been that security problems which aren't a)
identified as such with the magic word 'security' and b) don't have CVE
numbers shouldn't even have their fixes committed in case the bad guys
spot the fix (as far as I can tell). I'm trying to point out that even
when they're not identified as such, it's often quite easy to identify
them.