Report a vulnerability privately, never in a public issue. Open the repository's Security tab and choose Report a vulnerability. For the TheColliery/.github repository itself, that is Report a vulnerability; for any other repository, open that repository's own Security tab. Private vulnerability reporting is on for every public repository in this organization. There is no e-mail address for security reports.
What to expect: the report is read and acknowledged, triaged against the repository's scope, and disclosed once a fix ships. This is a small team, so there is no fixed response time. A public issue stays the right place for an ordinary, non-security bug.
A repository's own SECURITY.md wins where it has one: it names that project's scope and how it is verified.