Merge pull request #5085 from pks-t/pks/security.md SECURITY.md: split out security-relevant bits from readme