Security Advisory - who should I approach?

In a case of a security issue, regarding commonmarker with an extension - who should I approach for creating a repository security advisory?