Is doc/security.txt still relevant? Reuse for security policy/announce?

"John P. Rouillard" <[email protected]> Wed, 30 Nov 2022 02:26:09 -0500
Newsgroups gmane.comp.bug-tracking.roundup.devel
Message-ID <[email protected]>
Hi all:

I have been looking at security.txt. It looks like a lot of the info
there hasn't been changed since 2002. I think Richard implemented all
the things at the hyperdb level using roles for control.

I am having a tough time finding anything in here that isn't
implemented or alternative security designs that should not be
implemented. The only reference to the file is in upgrading.txt for
the 0.5.0 version.

I propose moving it to security-history.txt and changing the reference
in upgrading.txt to it.

I will create a new security.txt will include:

   Directions on how to report a security issue with Roundup (with a
   reference from the main Readme/index).

   References to security related sections in other documents
      (e.g. schema design in customizing.txt, file permissions
      in admin.txt, security fixes in upgrading.txt, etc.

   Security advisories (CVE) post 2.0.0.

Thoughts? Does anybody know if mercurial (and git) will be ok with
this rename and replacement?

--
				-- rouilj
John Rouillard
===========================================================================
My employers don't acknowledge my existence much less my opinions.