Usually I'd agree with everything you're saying. Look at the actual issues and the discussion on the first GitHub thread.
> We don’t know how they handled it. They may have handled the communication poorly, but regarding the security issue itself, we don’t know, because they didn’t tell us.
And maybe the moon is actually perfectly spherical, as God intended, being a heavenly body and all and those craters we see are actually filled in with an invisible undetectable substance.
Sarcasm aside, notifying users of an issue in a timely manner is elementary to security. Trying to sweep it under the rug does not make inspire even the smallest sliver of confidence in how they'll handle their next issue.
> You seem to be claiming that no software with any security features can have more than one security failure, ever.
No, but I do expect that a project that lists security as it's primary advantage [1] to at least make an integration test to make sure that files in encrypted folders/sub-folders are, you know, actually encrypted. If _any_ project out there keeps having the same bugs, then no, I would not consider them to be serious people either.
[1] https://nextcloud.com/compare/