[giallu: this whole section seems quite orthogonal to the packaging issue; of course distro packagers are interested in security issues/patches, but this list seems more suited for a security team, not a packaging one]
Manage the process of porting security bugs to the latest stable branch and make sure there are bugs to track such porting work (with summary starting with “Port:” prefix and adding a relationship of type “related”).
Make sure that security fixes have the required level of documentation to support the process of creating security advisories.
Maintain a list of sites on which we would like to submit our new advisories.
Decide and maintain the format of the security advisory.
Author and publish security advisories.
Make sure security bugs cross references security advisories (e.g. include CVE in summary).
Make sure security bugs are reported as private and are changed to public once a stable release is released.
Make sure the security category is used “wisely” in the bug tracker.
Duplicate security issues should be marked as such.
If there are N security issues that indirectly refer to the same issue, then they a parent issue should be created and that is the one that should be documented, fixed, included in the change log, and published as a security advisory.
Security fixes should include a description of the fix. It can be explanation of how to apply the fix, a patch, etc. This should allow packagers to apply the fix, users who are not ready to upgrade to also do the same.
Advisories that are hosted on the Mantis website will be hosted on the wiki and will be all linked from an index page. The index page should include a table with information like: date, CVE, bug #s, versions affected, and summary.