Use GitHub's private vulnerability reporting form:
Do not open a public issue for an undisclosed vulnerability. Include the affected MidTerm version and platform, impact, reproduction steps or a minimal proof of concept, and any suggested mitigation. Remove passwords, API keys, tokens, personal data, and unrelated repository content from the report.
For security hardening ideas that do not disclose an exploitable vulnerability, use the normal public issue tracker.