At the website and in GitHub security policies link to native GitHub vulnerability reports. These are way more convenient than using emails.