Otherwise, look at specific distro feeds. For example Ubuntu has http://www.ubuntu.com/usn/ (RSSable) and Debian has https://www.debian.org/security/ (also RSSable)
(apparently you can also generate your own feed from http://tif.mcafee.com/ but I never used it)
The big issue we see with RSS / mailing lists is a problem of discoverability and noise. Not all software has an easy to digest format for security changes. We want to do the scraping / parsing once and make it consumable by others. General lists such as OSS and distro specific security announce lists tend to have more noise. Most people only care about packages installed on their machines, which is why we filter our results based on your set of packages.
I think it is a good complement to the security advisories of your Linux distributor (Debian, CentOS, whatever), but is isn't free as you'll need time to keep an eye on it.
There must be many dozens of engineers who monitor mailing lists for issues in (let's say) ElasticSearch. They could be incentivized to share their findings.
Then if one source tags a certain CVE as significant, I get a ping. If several sources tag it, the ping gets more urgent. Eventually I feel scared enough that I upgrade.
In general, looking at the security information for a Linux/BSD distro containing the software you care about is probably the best way, along with tracking any RSS feeds you can find that do exist.