Do not report security vulnerabilities in a public issue.
Use GitHub private vulnerability reporting to report a vulnerability. Include the affected workflow, the expected result, the actual result, and the minimum steps needed to reproduce it.
The repository owner must enable private vulnerability reporting before the repository becomes public.
Use GitHub Issues for non-sensitive bugs and support requests.