Hi, all!
I put this on the wiki, but I think it should have more attention.
https://trac.torproject.org/projects/tor/wiki/org/teams/NetworkTeam/Security...
It's the draft policy that we're using to guide our action when we run into security issues in the program "tor". It's not finalized, but we've been trying to follow it as we notice issues in order to identify any problems in it. It's had some review already, but more is always welcome.
Have a look!