We need to define a standard for security overlay git repository that contain the upstream id and explanation.
We need also to define what to do, if there is need to add changes the patches.
Documentation is needed.
As now we are using this repository as standard