Jonathan,
> Here is a wiki I through together combining elements of both our
> current security page and thoughts from the Django one:
Thanks for getting this started! I've revised it heavily.
> One suggestion (not in the draft) is that when we do make release
> announcements containing security fixes, we do include the URL to our
> security policy to make it clear what it is.
Actually, we usually do provide a link.
--
Josh Berkus
PostgreSQL Experts Inc.
http://pgexperts.com