Once an issue has been fixed and released, an embargo of at least 3 months is starting to allow anyone working with XWiki to perform actions before the publication of the CVE. The embargo might be longer than 3 months, in which case extending the embargo might be decided through a vote on the forum. The sponsoring companies are automatically informed as soon as a security issues has been discovered through the security communication channels.
For example, if a security issue has been fixed and released in 11.10.2 and in 12.0, respectively released the 5th of February and the 29th of January, the CVE could be published 3 months after latest release: i.e. the 5th of May.
So in short, when you see that a release note mentions security fixes you know that you have at least 3 months after that to upgrade before the issues are disclosed.
For Bugfix releases we have the following release strategy:
For the LTS branch:
Try to release regularly without too much time spent between 2 bugfix releases (right now it’s left at the appreciation of the committers to review the list of fixed issues and decide when to release).
We allow to perform a release that has blocker issues fixed, even if there are still other important issues not fixed (including other blocker issues). The goal is to provide a LTS as stable as possible, as quickly as possible.
For other branches:
Left at the discretion of the committers to decide (it depends how close we are to releasing a new minor versions for example).