This issue tracks the creation of comprehensive CNA docs and policies. As needed sub-issues will be created to track work.
Current documentation is
https://github.com/openjs-foundation/security-collab-space/blob/main/cna-guide-for-openjs-maintainers.md