Report suspected vulnerabilities privately through GitHub private vulnerability reporting. Do not put credentials, authorization headers or private response data in public issues.
Fixes ship as new releases. A published version found defective is deprecated (npm) or yanked (PyPI, crates.io) and followed by a fixed release.