**Is your feature request related to a problem? Please describe.** There appears to be no way to understand what to do if there is a security bug **Describe the solution you'd like** Add a policy to the security tab **Describe alternatives you've considered** Can be in the readme but the security tab is probably best **Additional context** NA