Adopt Public Security Policy (Security.md file) to UXL.
You can use oneDNN as an example: Security.md
Pay attention to Supported Versions section, it may vary based on your Support policy.
Enable Private Vulnerability reporting
GitHub Security tab -> Enable Vulnerability Reporting
