This is the new disclosure process as discussed here: https://github.com/kubernetes/kubernetes/issues/35462
This relies on a doc to be merged into docs/devel/security-release-process.md but this doc can be reviewed in parallel.
You can find a draft of the content of that doc on #35462