It's not clear to me that FreeBSD found any of them internally ...
It's probably the right approach to onboard a few independent security companies and task them with reviewing multiple OSS projects than it is to onboard each project individually.
It's not clear to me that FreeBSD found any of them internally ...