Touch-up the security policy to make the OpenSSF scorecard slightly happier; https://securityscorecards.dev/viewer/?uri=github.com/docker/buildx Warn: One or no descriptive hints of disclosure, vulnerability, and/or timelines in security policy Signed-off-by: Sebastiaan van Stijn <github@gone.nl>