This is needed so that people know how to report security issues.
Closes gh-2103
--- /dev/null
+# Security Policy
+
+## Supported Versions
+
+The [latest released version](https://github.com/jquery/jquery-ui/releases) of jQuery UI is supported.
+
+## Reporting a Vulnerability
+
+Please email security@jquery.com, and we will respond as quickly as possible.
+
+If the vulnerability is considered valid and accepted, a patch will be made for the latest jQuery UI version. If the vulnerability is deemed invalid, no further action is required.