The OP explains what the ASF expects in this regard.
"In the case of Apache OpenOffice, needing to disclose security
vulnerabilities for which there is no mitigation in an update has
become a serious issue. In responses to concerns raised in June, the
PMC is currently tasked by the ASF Board to account for this
inability and to provide a remedy. An indicator of the seriousness
of the Board's concern is the PMC been requested to report to the
Board every month, starting in August, rather than quarterly, the
normal case. One option for remedy that must be considered is
retirement of the project. The request is for the PMC's
consideration among other possible options."