Hello.
In short: create a page that lists latest security bugs discovered/fixed in Drupal and contrib modules etc.
I know there is a security contact form, but the purpose of LATEST SECURITY BUGS page would be different.
Security contact form is meant for reporting security bugs. But there is no specific place for checking if your current drupal install has any known bugs or not.
Supposedly there was no "critical security problems" in Drupal so far, but as there are no programs without bugs this is going to change one day.
Also I believe bugs in contrib modules should be listed on such page. You host contrib modules on drupal.org and it's natural to host security advisories for such modules on drupal.org as well.
Currently, if one would like to check if there are any known security issuses in his drupal installation, one needs:
1. make a list of installed modules
2. check version/release date of each module (this can be impossibile sometimes!)
3. for each module he needs to check bugs for this module. He can't even compare versions as there are no project versions.
For example I have heard flexinode is quite popular module. And there was no information about latest critical security bug othere then this bug report: http://drupal.org/node/21820
It'd be nice if users didn't have to browse bug reports and other informations in searchfor security bugs reports but had one page that lists them all. It's common practice for mature and proffesional projects to have 'security issues' page.
If security issues were sent also to some specific read-only, low volume, open-for-all mailing list it'd be even better.
Comments
Comment #1
Cvbge commentedPlease see also http://drupal.org/node/12646 for similar issue (closed as "fixed" without implementing what the issuer requested). It has some nice rationale for such page.
Comment #2
beginner commentedI reoppened it with an additional comment...
I second your opinion, and hope it can be implemented soon.
I don't buy the "Drupal is secure and no security flaw has been found so far".
I hope a patch could be released for this security issue soon:
http://drupal.org/node/22872
In the Priority pull down menu, maybe a 'security' level should be added above 'critical'.
Comment #3
chx commentedhttp://drupal.org/security
Comment #4
(not verified) commented