process.</p></li>
<p>(This may rely on the other project(s) having
documented and responsive security contact points)</p>
- <li><p>We will prepare or check patch(es) which fix the vulnerability.
- This would ideally include all relevant backports.</p></li>
+ <li><p>We will prepare or check patch(es) which fix the
+ vulnerability. This would ideally include all relevant
+ backports. Patches will be tightly targeted on fixing the
+ specific security vulnerability in the smallest, simplest and
+ most reliable way. Where necessary domain specific experts
+ within the community will be brought in to help with patch
+ preparation.</p></li>
<li><p>We will determine which systems/configurations/versions are
vulnerable, and what the impact of the vulnerability is.
Depending on the nature of the vulnerability this may involve