There was a long discussion around mid-December on the private and
security Geronimo mailing lists about how to handle security
vulnerabilities. The outcome of that discussion (which is mainly a
boilerplate suggested by Mark Thomas for all projects to use) can be
found on our Project Policies wiki page at -
http://cwiki.apache.org/GMOxPMGT/geronimo-project-policies.html
If you see anything that needs changing or information that needs to be
added, then please discuss on this thread.
Thanks,
Apache Geronimo PMC