Part of the tidelift setup. In https://github.com/numpy/numpy/issues/13475 / https://github.com/numpy/numpy/pull/13485, NumPy decided to just link to https://tidelift.com/docs/lifting/security. That should suffice to us. Only thing to decide is who all gets notified with these reports.