Stop using the CVSS score to compute the priority of security issues

This vote passed with 5 committers answering, all with +1.

However, I’m pausing its implementation as we haven’t agreed on the handling of “Critical” issues in the parallel vote, meaning that we currently don’t have any process how we ensure that “critical” issues are handled in time to achieve the promised 90 days.

I’m still trying to find an agreement on a process for this, if this shouldn’t work, I’ll propose a separate process for “Critical” security issues (but I would really prefer to have a general process for all “Critical” issues).