Process: need to publish security policy
Another thing pointed out by @manu in his security audit. We need to publish security policy in a concise form and publish it in a standard github way. That basically means creating SECURITY.md file and enabling security reporting on github.
We already have Section 23.3 in ARM and KB article. Both look like great sources of info.