Brad Spengler
https://github.com/cisagov/vulnrichment/issues/262 Went from "We intentionally don't include CVSS scores or CWE identifiers in http://kernel.org CVEs, and we'd appreciate it if CISA's ADP stopped adding them." in January to effectively "if you don't do what we say by our deadline, we're going to...