Use GitHub private vulnerability reporting when available. Otherwise, ask the maintainer for a private contact without posting vulnerability details publicly. Include the app revision, macOS version and steps using example links. Never include passwords, meeting passcodes or other private data.