Getting this wrong in a core product is one thing. But then also not fixing it for over half a year? Sigh...
Remember how this "recent" critical Mail vulnerability also didn't get fixed for months? It's really putting me off at that point.
I also like the tick-tock release schedule idea.