A fork of a project that does security patches only is an interesting idea...

Since then a diff of the two projects will be a perfect list of security issues and will make designing an attack rather easy...

Only until the next feature lands in upstream, likely accompanied by some refactoring.