(Tailscale CEO) I don't know what to tell you. The problems that are found internally, or via security reviews and pentests we pay for, are ones that we fix before releasing. They don't need bulletins.
Bugs that are found by other people are found, by definition, after release. They are therefore more likely to need a bulletin.
> The problems that are found internally, or via security reviews and pentests we pay for, are ones that we fix before releasing.
Either you didn't mean what you wrote, or you are saying that you never find problems internally after release.
But why should insecure argument handling bugs (as per your recent SSH bulletin) be found after release ?
Those are an ancient class of bugs that should be picked up by any competent security review.