Do not use public issues.
Use private advisory flow on affected repository:
https://github.com/silkietools/<repo>/security/advisories/new
Include:
- Affected repository and component
- Steps to reproduce
- Impact assessment
- Any suggested remediation
Maintainers triage by severity and exploitability.