Theres some information here they've put out: https://www.debian.org/security/faq
And yeah it must be an incredible amount of work to stay on top of all this