We do not claim to be security experts, however, we do our best to fix security issues asap, and provide patch releases or patches to fix them in already existing releases. To inform us about security issues, please use the following channels:
Report the issue in the bug tracker as a PRIVATE bug. This will avoid the bug being available to others before it is actually fixed by the team members and a patch is provided.
Report the issue via the security mailing list. This list is private and is only project administrators are subscribed to it.