RT GitHub Security Lab
Being transparent about potential security vulnerabilities helps increase trust in your project. We believe it's much better to request a CVE and publish a security advisory than to stay silent and hope for the best, even for low severity vulnerabilities.
https://github.co/3v5a801
https://twitter.com/GHSecurityLab/status/1517550486894825472