Security vulnerabilities are only considered important if they are present in the utility in the way it is made available to end users. Specifically, the utility is made available through a rolling release model: as soon as updates are considered ready for end-user consumption, they are made available to users and it is assumed that users are using the latest release of the software.
To report a security vulnerability, please follow the instructions at https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability.