Use GitHub private vulnerability reporting: open the Security tab of the repository and select Report a vulnerability. It opens a private thread with the maintainer. Do not open a public issue for a security problem.
Include the version or commit, the platform, and steps that show the problem. Remove secrets from logs before you attach them.
You get a first reply within seven days. A confirmed problem gets a fix in a release and a GitHub security advisory that credits you, unless you ask otherwise.
The latest release on the releases page gets fixes. Repositories without releases get fixes on the default branch.
In scope: the code in the repository, its release pipeline, and any update channel it ships. Out of scope: third-party services and tools the project calls.