[meta] add `SECURITY.md`
diff --git a/.github/SECURITY.md b/.github/SECURITY.md
new file mode 100644
index 0000000..82e4285
--- /dev/null
+++ b/.github/SECURITY.md
@@ -0,0 +1,3 @@
+# Security
+
+Please email [@ljharb](https://github.com/ljharb) or see https://tidelift.com/security if you have a potential security vulnerability to report.