Update SECURITY.md - Bring it up to par with the one in server
#241
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Offshoot of nextcloud/server#40966.
One caveat: I think the line added in 6c45691 in the existing Security Policy was probably trying to accommodate maybe either some of the "hosted" but still fairly independent sub-projects and/or maybe a way to accommodate reports about third-party maintained apps.
a) Is my guess accurate?
b) Should we try to accommodate that still?
c) If so, maybe we can find a clearer way to state that?
If a/b/c === true then we can add it to this PR before it gets merged if deemed appropriate.