Through an interview on SecurityFocusStefan Esser has just announced his plans for the "Month of PHP Bugs" (MOPB?) during March 2007.
It would be interesting to see what issues he discovers, hopefully most of them have already been reported to the PHP Security Team, in which case the upcoming 5.2.1 release will provide a resolution path for affected users. Hopefuly, unlike the MOAB and MOKB, the reported issues are not going to be infamous 0-day vulnerabilities. If they are however, which would be unfortunate, I think we'd be looking at a security fix only release in April, while releasing patches to address individual issues on a daily basis.
Either way, I have to look at this as a free security audit of PHP by someone with a clue about security and ultimately, in the long run it will only make PHP better, even if March is going to be rather busy
I fear that the issues will not be disclosed to the PHP dev team in advance. They will probably be fixed by the Suhosin patch so that you could also call it the "Month of Suhosin Promotion" (MOSP). Just speculating, of course.
Except for the fact that he WAS part of the PHP dev team, and he's reported almost all of the 31 issues, many of which have been known for YEARS. His security concerns have been largely ignored by them, which is why he resigned. What else is there to do but start publicly reporting the bugs? I think it's great; it'll pressure the devs into fixing their code like they should've done the first time the bugs were reported.
Hopefully he'll post patches along with the reports.