[eclipse-pmc] Disclosing resolved vulnerabilities

Greetings Eclipse PMC. There are several bugs marked "committer-only" in
Bugzilla [1]; some have been so-marked for quite a while. These need to
be disclosed at some point.

I have posted a draft of a security policy [2]. In the policy, I have
suggested a minimum time-to-disclose of three months. But I have left
considerable latitude for the PMC to make their own policy decisions.

How do you plan to handle these bugs?

Your comments on the Security Policy are most welcome. Please post your
comments on Bug 337004 [3].




