Do not report security vulnerabilities in a public issue.
Use GitHub private vulnerability reporting to report a vulnerability. Include the affected workflow, the expected result, the actual result, and the minimum steps needed to reproduce it.
Use GitHub Issues for non-sensitive bugs and support requests.