Add SECURITY.md to document how to report vulnerabilities privately.
Since showmycode's purpose is sharing private code without exposing credentials, a clear disclosure path matters — and Private vulnerability reporting is already enabled on the repo, so this gives it a front door.
The policy directs reporters to the Security tab instead of public issues, sets a rolling-release support scope (latest main), and lists in/out-of-scope issues specific to the threat model (PAT exposure, share-token bypass, allowlist bypass, auth weaknesses).
N/A
SECURITY.md and confirm the "Report a vulnerability" link points to the repo's Security tab.feat:, fix:, chore:, refactor:, docs:, i18n:)locales/ko.json and locales/en.json (if UI text changed)