Do not disclose credentials, personal data, private conversations, or exploitable details in a public Issue.
If GitHub's private vulnerability reporting is enabled for the affected repository, use it. Otherwise, provide only a non-sensitive summary in an Issue and wait for a repository-specific private contact path.
There is no general guarantee of security support for prototype repositories. Check the affected repository's README and status before relying on it.