The security page of a certain Nix issue should: - [x] be accessible via `website.tld/$tracking` - [x] informs about the current status: awaiting-mitigation, mitigation-in-progress, mitigated, wontfix on each supported channel. - [x] list all maintainers, grouped by package - [x] list all known vulnerabilities - [x] grouped by package For maintainers (or more): - change status. - performs any operations: bump the package in that channel (unstable or stable X), add/remove a known vulnerability as a new PR. For security team: - admin access.