I believe there are some legitimate cases where a CVE fix ticket might be kept private to avoid exposing a potential vulnerability or fix before the patch is published, but that’s up to the devs. It should be published to the security advisories site soon though.
Could TrueNAS please post an update on patching runc to mitigate these CVEs? I still don’t see them even mentioned on the security advisory website. (security dot truenas dot com for those wanting to follow along)
Caching issue. I see it now after a hard page refresh. The XHR request to fetch SCALE.json was being loaded from cache in Firefox. Might want to append the timestamp to the request in the page javascript, i.e. from index.html