Tagging a few different groups for review here, as the new standard for OpenSSF Scorecard subproject security policies should be something along the lines of:
Ironically this may cause subprojects to only score a 9/10 for Security-Policy based on the last point being awarded for certain terms. (Personally I find that scoring a little too picky but that's how it is currently)
Originally posted by @spencerschrock in https://github.com/ossf/scorecard/issues/4212#issuecomment-2207220718