No, that's the place where you get an identifier for the issue. You still need a place with answers to frequently asked questions, more details as to how the attack works, artifacts and proof-of-concept code, etc.
I'm sure keen folk can digest SCM pull requests, but that population is a super minority I think to well presented content disseminated on youtube, sites, blogs, etc.
I don't think CVE being mandated as the only place vulnerability/conversations are had would be optimal, no?
I know HN frowns on grammar-policing comment, and rightly so; but I thought nonetheless you might like to know (and it looks so much more formal this way anyway!) that it's "smörgåsbord" (or the diacritics are commonly omitted in English).