Do not open a public issue for a suspected vulnerability.
Report it privately through the repository security advisory flow, or use the maintainer contact channel listed on GitHub once the repository is published. Include the affected package and version, a clear description, reproduction steps or a minimal proof of concept, impact, and known mitigations.
Security fixes target the latest default branch and the latest published package version.