>The Debian security team cannot monitor the mailing lists for every project
>in Debian: there are literally thousands.  We rely on channels which are
>explicitly devoted to the dissemination of security announcements (e.g.,
>BUGTRAQ), and communication through the Debian package maintainer (who
>should follow the relevant mailing lists for the project).
>I do not think I have ever seen a security announcement from the
>Squirrelmail project on a public mailing list.

I completely agree with Matt. This was the idea I wanted to say in my
former post. Don't mix development docs (like changelog) with security
ones (security advisories, etc). IMHO, the correct procedure for
SquirrelMail (or other important project) would be to open a security
section where security announcements were placed and sending _also_
these announcements to security lists (at least, Bugtraq). I'm not a
developper but this is exactly what I usually do if I discover a
security related bug in any piece of software.


