pretty much directly applies. But one thing I have run into in other situations is single point of contact, and the person leaves/etc. I'm thinking for the case of a lot of smaller Open Source projects you usually have a main developer so I think a single point of contact being a problem is moot here (since without them the project won't get updates, let alone CVEs). I was wondering what other people thought?
--Kurt Seifried -- Red Hat -- Product Security -- CloudPGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993Red Hat Product Security contact: secalert@redhat.com