> For the record, if you have a sensitive security issue, please mail
>     secur...@exim.org

well, that's good to know, I guess, but may I suggest you put that on the
website somewhere? Just put a text file in
https://www.exim.org/static/doc/security/ or something, that's linked as
"security" from the start page, so that should be easy enough to discover.

Even knowing the address, the only thing I can find on the web containing
that address are some files in /.github/ in the repo, hosted on github, so
that's kinda impossible to find.

Adding a file in the root of the repo might also be a good idea ...

Regards, Florian

