My heart goes to all the statically linked and variously packaged and containerized software installations that will never see an update to their copy of libwebp, this remaining vulnerable forever.
Yes, I find reporting to downstream packagers (a.k.a. distributors) extremely relevant! When your favorite #SoftwareCenter or #PackageManager is all for linking to upstream, but not to those who directly affect your package in a supply chain, as a result, tops like in #KeePassXC get all the pinecones: there is no enthusiasm in an average user to link back those issues to downstream, not with the p(l)ain text and how derivatives are communicated anyway... 
#software #SoftwarePackage #SoftwarePackages #SoftwarePackageManagement #PackageManagement