github claims there was no security policy
diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 0000000..c420962
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,3 @@
+# Security Policy
+
+Please see https://ant.apache.org/security.html