Security

Start with the threat model and the reporting policy. Do not file public issues for exploitable vulnerabilities.