53ebeb4cf1
Add docs/SECURITY-DISCLOSURE.md describing how vulnerability reports are handled end to end (private fix, cross-platform validation, reporter verification, patched release, then a GitHub Security Advisory with a CVE and credit). Update SECURITY.md: add GitHub private vulnerability reporting as the preferred channel, replace the over-tight 48h/7-day commitment with honest best-effort targets for a solo-maintained project, add a safe-harbor statement, and refresh the stale supported-versions table (0.5.x -> 0.8.x). Signed-off-by: Martin Vogel <martin.vogel@datadice.io>