Wikibase and many software components (MW extensions and other things) included in Wikibase release packages are not included in Mediawiki's bundled extensions/skins, and as such security fixes are not released by the WMF teams, even though the security issues might be patched for Wikidata and other WMF wikis.
In order to allow non-Wikimedia users of Wikibase software suite, we want to make security fixes publicly available.
It seems sensible to adopt the process of releasing security fixes similar to the one WMF uses for Mediawiki and "bundled extensions".
General overview of the steps in the process is included in https://www.mediawiki.org/wiki/Reporting_security_bugs#What_Happens_When_Security_Issues_Are_Reported
Some technical details from https://wikitech.wikimedia.org/wiki/How_to_deploy_code#Security_patches about deploying security patches to WMF wikis might provide some inspiration as well.
There might be also some relevant pieces of information or process in WMF Security Team's draft of the Security patches with Gitlab: https://www.mediawiki.org/wiki/GitLab/Workflows/Security_patches
Open Questions to answer:
- What software "components" should be covered by this? WMDE-owned software only?