From the OpenSSF Best Practice requirements:
- The project MUST publish the process for reporting vulnerabilities on the project site. (URL required)
- If private vulnerability reports are supported, the project MUST include how to send the information in a way that is kept private.
Example: https://github.com/helm/community/blob/main/SECURITY.md
From the OpenSSF Best Practice requirements:
Example: https://github.com/helm/community/blob/main/SECURITY.md