Consider an open source project that is under continuous development. During development, in your day-to-day work you do occasionally find some issues on your own. There are also users of your library reporting issues.
If a security advisory shall be published: which defects shall be taken into the advisory? Only the ones reported from extern? Or also those you discover on your own?
Are there any references/guides for this topic?
Edit: I'm not asking for how to do a responsible disclosure when I found an issue in another library! The core of the question is whether also issues shall be published in an advisory that were not reported from externals but found during your day-to-day work in your software.