There's an entry on the release notes [1], the changelog, etc; but unless I'm missing it, looks like there's not really proper management of security issues (same thing for the recent crypto.cat bug).
May be I'm old-school but when a project goes over certain size and there's no prominent "security" section (as important as downloads, IMHO), that's a red flag for me.
This is the way you do it:
- http://httpd.apache.org/security_report.html
- http://openssh.org/security.html
- http://nginx.org/en/security_advisories.html
All projects doing sensible tasks have a security history. Don't hide it, make it public and accessible to your users.
[1]: http://docs.saltstack.com/topics/releases/0.15.1.html#rsa-ke...