Most security fixes in an open-source RTOS land as ordinary bug fixes — merged, released, and never flagged as security. zepsec finds those fixes in Zephyr, analyses each one against the real source tree to decide whether it closed a genuine, exploitable vulnerability, and drives the ones that did through to a published advisory: a GHSA draft and a CVE record, backports onto the maintained release branches, and the release notes. Advisories are reviewed and published by the Zephyr security subcommittee; this service never publishes anything itself.