I suppose that the author is the best to follow security updates, but if he doesn't follow them, others can do it.
I recall two rpm in nethforge, phpmyadmin and wordpress, concerning the security purpose the most of time it is to push new dependencies from epel to nethforge.