Should we create a separate (private) security list? Pros: 1. current private list is PMC only; other contributors can subscribe to a separate list to collaborate on security issues 2. easier to organize security-related issues separately from project management activity 3. follows a standard convention for security reporting
Cons: 1. another mailing list to moderate 2. another mailing list to subscribe to 3. would need to update docs and website to make the list's existence known Thoughts?
