Commit bb5e04a1 for libheif

commit bb5e04a1c93d5e421e0936374fc11e01930f6768
Author: Dirk Farin <dirk.farin@gmail.com>
Date:   Mon Oct 5 18:44:42 2026 +0200

    Update the 2026 advisory and release counts after v1.23.6

    With the 12 advisories of v1.23.6, 73 security advisories were published
    for libheif from January to October 2026 (4 rated critical, 24 high), and
    v1.23.6 is the tenth release that was made mainly to ship security fixes.
    The project status note in the README is dated October 2026.

diff --git a/README.md b/README.md
index 00813311..02ef36a1 100644
--- a/README.md
+++ b/README.md
@@ -15,8 +15,8 @@ For AVIF, libaom, dav1d, svt-av1, or rav1e are used as codecs.
 libheif can be built with a subset of the supported codecs to keep the size and the number of dependencies low.
 Alternatively, the libheif codecs can also be built as separate plugins that can be installed and loaded dynamically when used.

-> **Project status (September 2026).** libheif and libde265 are maintained by a single independent developer with almost
-> no recurring funding, while 61 security advisories had to be investigated, fixed and released in 2026 alone.
+> **Project status (October 2026).** libheif and libde265 are maintained by a single independent developer with almost
+> no recurring funding, while 73 security advisories had to be investigated, fixed and released in 2026 alone.
 > If libheif is part of your product or service, please read [Funding](#funding) and [Commercial support](#commercial-support).
 > Security issues are reported as described in [SECURITY.md](SECURITY.md).

@@ -438,8 +438,8 @@ libheif and libde265 are developed and maintained by me, Dirk Farin, as an indep
 The libraries are used by practically every open-source application and service that handles HEIC or AVIF
 files (see [Software using libheif](#software-using-libheif)), but the maintenance work is almost entirely unfunded.

-From January to September 2026, 61 security advisories were published for libheif, most of them found with
-automated tools by organizations that use libheif in their products, and nine releases were made mainly to ship
+From January to October 2026, 73 security advisories were published for libheif, most of them found with
+automated tools by organizations that use libheif in their products, and ten releases were made mainly to ship
 security fixes. Each fix means reproducing, fixing, testing, fuzzing and releasing, currently done in evenings and
 on weekends. Details are in [SECURITY.md](SECURITY.md).

diff --git a/SECURITY.md b/SECURITY.md
index 6298f8b4..fdbd3308 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -152,8 +152,8 @@ The following are targets, not commitments (see [Maintenance capacity](#maintena
 libheif and libde265 are maintained by one independent developer, largely in unpaid evenings
 and weekends. There is no security team.

-To make the workload concrete: from January to September 2026, 61 security advisories were
-published for libheif (4 rated critical, 20 high), and nine releases were made mainly to ship
+To make the workload concrete: from January to October 2026, 73 security advisories were
+published for libheif (4 rated critical, 24 high), and ten releases were made mainly to ship
 security fixes. Most of the 2026 reports were found with automated or AI-assisted tools,
 often run by organizations that use libheif in their products.
 Reproducing, fixing, testing, fuzzing and releasing each fix takes hours to days.
diff --git a/funding.json b/funding.json
index 32c9bbfe..2c98a8e5 100644
--- a/funding.json
+++ b/funding.json
@@ -7,7 +7,7 @@
     "name": "Dirk Farin",
     "email": "dirk.farin@gmail.com",
     "phone": "",
-    "description": "Author and sole maintainer of libheif (HEIF/AVIF file format library) and libde265 (H.265/HEVC decoder). These libraries are used by practically all open-source software that reads or writes HEIC and AVIF images, including ImageMagick, GIMP, libvips/sharp, Pillow, darktable, digiKam, GDAL and the GNOME and KDE desktops, and through these by a large number of web services and image pipelines. The work is currently almost entirely unfunded: in 2026 alone, 61 security advisories had to be investigated, fixed and released in unpaid evenings and weekends.",
+    "description": "Author and sole maintainer of libheif (HEIF/AVIF file format library) and libde265 (H.265/HEVC decoder). These libraries are used by practically all open-source software that reads or writes HEIC and AVIF images, including ImageMagick, GIMP, libvips/sharp, Pillow, darktable, digiKam, GDAL and the GNOME and KDE desktops, and through these by a large number of web services and image pipelines. The work is currently almost entirely unfunded: in 2026 alone, 73 security advisories had to be investigated, fixed and released in unpaid evenings and weekends.",
     "webpageUrl": {
       "url": "https://github.com/farindk"
     }