Was there any discussion surrounding this vulnerability?
A discussion can include debates, disputes, or polite talk about how to
resolve uncertainty.
Example include:
* Is this out of our scope?
* Is this a security problem?
* How should we fix this?
Just because you see multiple comments doesn't mean it's a discussion.
For example:
* "Fix line 10". "Ok" is not what we call a discussion
* "Ping" (reminding people)
Curators were instructed to check the bugs reports, pull requests, and mailing lists archives.