One of the folks behind the bounty here. Happy to answer questions.
I appreciate the goal of using languages better suited to memory-safety, but when I look at CVE lists including the same recurring projects I can't help thinking that the bounties here are not going to help.
(For example imagemagick/graphicmagic, the linux kernel, even wordpress/jenkins plugins, and similar things are regular candidates for security issues - and they're not going to get rewritten/modified-in-place to use rust/golang any time soon.)
We have to approach this as a question of how, not if. When we do that, we can change computer security.
Pretend I wrote gstreamer, wireshark, or similar.