DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
The release notes MUST identify every publicly known run-time vulnerability fixed in this release that already had a CVE assignment or similar when the release was created. According to ASF policy advisories are published 'at the same time as or after' a release. The Best Practices badge narrows this to 'at the same time as' the publication of release notes. For ASF projects this typically means the CVE will not be part of the release notes at the time of voting for the release, but are added when the release notes are published along with the release.
...