Change SECURITY.md to hint for acceping vulnerability reports via the GitHub mail
This seems to be a new feature and I've had this tested (with a different account) that this can be used by anyone.
IMHO, this is a convenient feature, as we'd need to publish it anyway there.