| # Security Policy | |
| If you have discovered a security vulnerability in this project, please report | |
| it privately. **Do not disclose it as a public issue**. This gives me time to | |
| fix the issue before public exposure, reducing the chance that an exploit will | |
| be used before a patch is released. | |
| To report a security vulnerability use the [Tidelift security | |
| contact](https://tidelift.com/security). Tidelift will coordinate the fix and | |
| the disclosure of the reported problem. |