Yes they did.
“despite having found literally thousands of new vulnerabilities (only a fraction of which were reported to Open Source projects, by the way), I don’t think that we’re any safer than before. That’s because finding vulnerabilities has never been the bottleneck in information security. The bottleneck isn’t even verifying a vulnerability report and validating its severity, as time consuming as that is. The bottleneck isn’t determining the fix, creating the patch, or publishing a new release. The bottleneck is still, as ever before, getting the goddamn packages updated. Patching is still hard”
https://www.netmeister.org/blog/everybodys-lost-their-minds.html