If you think you have found a vulnerability in a roobli project, report it through GitHub's private advisory form on that repository. Do not open a public issue with a working exploit.
For Noto: https://github.com/roobli/Noto/security/advisories/new For the canvas kit: https://github.com/roobli/canvas/security/advisories/new
We will not publish a bounty schedule. If the report is real, we will answer.