The short summary of if it has been worth the hassle: yeah I think so. It is now easy and fast to get new CVE IDs. We have a seat at a table where I can complain loudly on the system and what I say actually might have a (small) impact.
We have yet to deny someone else's crazy CVE attempts against curl.
#curl has been a CNA for a year now https://daniel.haxx.se/blog/2024/01/16/curl-is-a-cna/
"Free Copilot in your GitHub account" is the 2020s version of "Free U2 album on your iPod".
Can you find an ITW 0-day from crash logs? Project Zero finds out