This is a scientific computing codebase, not a network service. Still, report issues that could affect users running the code, including unsafe file handling, unexpected code execution, or supply-chain concerns.
Use GitHub private vulnerability reporting if it is enabled on the repository. If it is not enabled, open a minimal public issue without exploit details and ask for a private contact path.
Until the project has releases, security and correctness fixes target the main branch.