@OmegaPolice @alexanderkjall yes and the majority of Linux kernel development is not volunteers, its a consortium of vendors organized through the Linux Foundation trade org which _does_ pay people. There are still volunteers who work on Linux but they shouldn't be a shield for the majority to pretend they are "just a smol bean, uwu" and dont have some responsibilities.
I'm the *first* to say that dragging volunteer FOSS maintainers is shitty (and that volunteers shouldn't cosplay as commercial vendors, by doing things like having public issue trackers, as it is nonsense to "open a support case" with a tracking number against a *volunteer*) but Linux kernel has volunteers it is not a volunteer led project anymore, its a consortium of major companies which benefit from pooling effort and having a neutral forum to collaborate.
I think security focused people, whose customers are also prioritizing security sometimes dont have empathy for or understand people who don't have security as their top priority, and treat people who don't share their priorities as stupid and incompetent, rather than understanding the differences in goals and constraints. That said there is probably room for improvement on kernel security, but more from a better systematic approach to prevent defects than treating every bug with a website as some super secret special thing. the current design makes a constant stream of local exploits inevitable