Apache Software Foundation released its Security Report for 2019, and it shows how it dealt with 620 threads across all projects.
320 of the reports were over vulnerabilities, and only 19 of those are still open in "triage", and usually processed within 90-days. Some low priority updates are held over until the next pre-planed updates.
[
blogs.apache.org...]