* add SECURITY.md as requested in #1018 * SECURITY.md: do not advise to report security issues publicly