@calle No one ever said you disclosed which projects you scan.
@aljaz was simply saying to stop signaling that you're finding critical vulns because this can act as an incentive for ill-intended hackers.
You're basically putting extra pressure on the red team by saying "we've found bugs".