...
- Open a JIRA "private security" issue. It must be an issue, not just a change in "type". Just changing the type doesn't help.
- Don't open pull requests; do a direct commit. (David construct email on creating private repo for more extensive commit processes when needed).
- Cut the security releases including release notes.
- Community Notification
- After announcement, create JIRA's.
- Three possibilities:
- No grace period - Everyone knows before people can patch + poeople who follow many projects on bugtraq know right away
- 15 business day grace period - People watching bugtraq will be unhappy with what looks sloppy reporting + Lets adopters try to patch first
- short grace period - People don't really have time to benifit.
- Public disclosure: bugtraq
...