OpenSSL 3.0.x vulnerability

Is there anything Make users need to know about the announced critical vulnerabilities in OpenSSL 3.0.x?

Will Make be issuing a statement?

I need to get a report to my infosec team and an official statement from Make would go a long way!