It has been requested by the Podman maintainers that Podlet have its own security policy. Currently, the security policy links to the general one for the containers org as that was what was originally requested when Podlet moved to the org.
I suggest that Podlet primarily use the security vulnerability reporting on GitHub. I have enabled private security vulnerability reporting for the repository. We could also add contact information to the requested MAINTAINERS.md file and direct security reports there. In terms of announcements, vulnerabilities can be described in the notes for the release that contain the fix.