I develop app which will use SharePoint/OneDrive to access user or group data. I recently found a behavior which can lead to data leak. I would like to know if the best solution is to share the project GitHub the private link to Microsoft team member or if there is any other type of procedure.
Please let me know if you have the answer.
You can try Microsoft Bug Bounty Program and report the issue
Either Microsoft Identity Bounty Program or M365 Bounty Program.
I have no experience with reporting a bug but you will need to describe the steps that lead to data leak, including some example.