Report suspected vulnerabilities privately to team@nonos.systems (or ek@nonos.systems). Please do not open a public issue for a security bug before it has been fixed.
The full policy, the scope, and what to include in a report live in the documentation: security/reporting.