We need to create an AboutCode.org level security policy and reference it on each of our projects. Some useful resources (GH context) are: - https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository - https://repos.openssf.org/principles-for-package-repository-security - https://github.blog/security/vulnerability-research/a-maintainers-guide-to-vulnerability-disclosure-github-tools-to-make-it-simple/