Call out the security reporting info in the CONTRIBUTING file
diff --git a/CONTRIBUTING.rst b/CONTRIBUTING.rst
index 9f63250..2a71dae 100644
--- a/CONTRIBUTING.rst
+++ b/CONTRIBUTING.rst
@@ -13,3 +13,10 @@
 ``docs/contributing.rst``, or online at:
 
 https://cryptography.io/en/latest/contributing/
+
+.. attention::
+
+    To report a security issue, please follow the special `security reporting
+    guidelines`_, do not report them in the public issue tracker.
+
+.. _`security reporting guidelines`: https://cryptography.io/en/latest/security/