Update security.md with details about the security branch sync
Not sure this is very clear, but I did this mistake today: I merged security
into master
after the security release of yesterday, but in the meantime, there was a security fix merged to security
that isn't yet released in a tagged release. Cherry-picking the released MRs should prevent that.
Of course, master
should still be merged tosecurity
regularly.