@bagder "Not worth writing, not worth reading" has a delightfully similar cadence to "not my circus, not my monkeys", and in the last year or two it's given me about the same peace of mind.
Of course, for vuln reports, you have to be less picky about who's reporting and what tools they use, as long as the bug is real. A bug's a bug. But in a context where hundreds of people are throwing big token budgets at a single project and largely reporting duplicates, I'd guess the odds of missing something important from a reporter who didn't even bother to write the ticket (let alone do their own dupe-checking diligence) are pretty sparse.