**Motivation** Where does one report serious security issues or vulnerabilities? **Desired Outcome** A `SECURITY.md` document or policy as GitHub recommends perhaps? **Alternatives** Not sure? Leaving it ambiguous doesn't seem optimal.