Check the supported versions in the README.md file of the individual projects.
Vulnerabilities are to be reported as normal GitHub issues. In the issue indicate if there is an active exploit of the vulnerability. Maintainers of the project are monitoring the reported issues, prioritize security advisories and provide a fix as soon as possible.