add security fixes to changelog