Version tracking and security alerts?

Where I work is currently investigating expanding into application management. I'm doing a proof of concept around a software information library that includes, for each app, details on how to track new versions and where to subscribe to security alerts.

The Dopus team seem to have their act together, so I thought I'd ask here. For Directory Opus, is there a feed or email list that provides a timely updates for each new version, ideally with nothing else in it? And is there a way of receiving urgent security notifications if there's some sort of compromised version or other security issue, and only security alerts (no other marketing or updates)?

I've already developed a system to parse new versions of the (soon to be retired) WFBS from a Trend RSS feed, and that's been a good solution for general version stuff. I suspect something like a mailing list for security alerts would be a common solution, or if security information is already being sent to a trusted 3rd-party service that does public security announcements, that would work too.

While I'm posting, is there an old version with a security problem such that you would recommend avoiding it, or only using something newer?

The JSON feed for the forum's stable-release tag is probably the closest thing to that:

https://resource.dopus.com/tag/stable-release.json

Not that I can think of, outside of extremely old versions.