We should have some format and or mechanism to identify bugs that are security in nature. example: Summary libxml: CVE-2015-xxxxx or have a flag to denote this issue is security related. We use 'security' in a keyword field.
Put the CVE-XXX-XXXX in the whiteboard, and then search for bugs with CVE- in the whiteboard?
Need a review of Security items in Triage meeting.
See https://wiki.yoctoproject.org/wiki/Security