Report privately through Security → Report a vulnerability on this repository, not in a public issue. Include the revision, the input that triggers it, and the impact.
Small project, no bounty. Expect an acknowledgement within a few working days.
main is the only supported branch. There are no backports.
Renovate keeps dependencies current. A vulnerable transitive dependency is reported the same way as anything else. Say what the exposure is, since a CVE in a dev-only tool and one in the runtime path deserve different urgency.