GitHub is adding private vulnerability reporting for open-source projects https://github.blog/2022-11-09-everything-new-from-github-universe-2022/
Everything new from GitHub Universe 2022 | The GitHub Blog

See what we're building to enhance the most integrated developer platform that allows developers and enterprises to drive innovation with ease.

The GitHub Blog
@kylealspach looks like it's disabled by default unfortunately, hopefully that's only until general release!
@kylealspach not to be negative about such an important feature introduction of course
@ajxchapman it's a good point to raise, it didn't come up when I spoke w/ them about it so I didn't realize that