There's no law that you have to fix all bug reports. Isn't it better for users and developers alike that they can see the problems of the project. If they don't have resources that's fine, it's not like they are charging money for their product. But why not be honest and not request people sweep bugs under the rug for fear of looking bad?
There is no law you can't complain about lack of help on Twitter
Also, could you quote the request to sweep bugs under the rug?
The main ask seems to be "send patches" later in the thread
Because it burns out developers and ruins the project. Its like how the treatment can be worse than the disease in medicine.
The CVEs get reported, then big corps automated systems start flagging all use of ffmpeg, the big corp security software stops builds and removes it from dev laptops, then frustrated big corp engineers start harassing the volunteers and soon its not worth volunteering anymore, and the project dies, and there was never a real world impact.