report a fault
bugs, questions and patches: the issue tracker.
vulnerabilities: not the issue tracker. the disclosure process and contact are in the security policy:
reporting a vulnerability (security policy)
if you try usv and it breaks, that report is wanted, not tolerated. a first release earns its second one from exactly these.