**Description of issue or feature request**: Similar to [go-tuf](https://github.com/theupdateframework/go-tuf/issues/371), we should create a [security policy](https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository) so that researchers can properly disclose security issues.