I figured you were referring to long term support but never heard that terms of android kernels before.
All android kernels are (supposed to be) based on LTS. Vendors just don't end up patching them fast, if at all. not a good thing.
Also I'd like to respectfully disagree with your statement on making sure I keep up to date and that's it's all things I MUST do.
Firstly this is a beta. When we get the weeklies rolling I'll keep on top of CVEs etc.
Secondly if people don't like the security of this ROM I don't really care. I'm not forcing anyone to flash it. This is an open source project for anyone to contribute. It is not my job to be trying to make sure I develop things and merge patches the minute they become available. In fact none of this is my job.
I'll merge security patches when I have time. And if someone wants to add PRs to get them in quicker they are welcome to do so. But if someone has the means to help out but only wants to criticize then please take discussions elsewhere.
#1 - I wasn't criticizing, in fact; I said it was great to see some Oreo rom development Happening... What I did was; pointed out that your kernel isn't up to date (by a month, not a minute) * That's not a criticism, it's just a fact.... && I made some suggestions on how to rectify that and provided you with some additional potentially useful information on LTS ~ thinking it may be helpful to you...
I also mentioned the signature signing because in the past I've seen ROMs on XDA haven't been signed properly - because the people who built them skipped that important step or didn't know any better. (not implying you, but; you would know 100% -> one requires generating your own private keys, one doesn't).
#2 - I never said you "MUST" do anything. Please go back and re-read what I actually wrote... I suggested that you probably *should* merge the monthly patches from Google and suggested possibly making use of LTS, As something that *should* be a priority (not *must* be). Monthly patches and LTS exist for a reason.... But yes; At the end of the day, your right ~ It's entirely your choice..... It's also one of the reasons, why I tend to avoid flashing custom roms -> you have zero idea whether the people cooking them up have actually done things properly (again, not talking about you, just a general statement).
#3 - I gave you a valid reason why I wouldn't be doing a pull request; I'm working on my own kernel, I'm busy && It's not my responsibility. What IS my responsibility to make sure that any kernel that I release IS patched and up-to-date. *It doesn't matter that it's not my job; I'm putting it out there for other people to use on their device; which typically contain loads of personal info, mobile banking, accounts, contacts, etc... So even with a disclaimer added; I still put in the extra effort. Because it's important.
Regardless, the whole thing of getting up-to-date and even merging LTS (if you chose to do so) takes maybe 10min. ~ not exactly something that you need me or anyone else to do for you or a pull request for. ~ It would take me longer to fork/grab your sources, pull in all of the commits and do a pull request... See why I'm not doing it now? Anyway, good luck with your ROM.