Questions and ideas
Use GitHub Discussions for anything that is not a bug: how to do something, whether a feature fits, or a comparison with another crate. Questions asked there help the next person who searches for the same thing.
Bugs and feature requests
Open an issue in the repository that owns the behaviour. The library, the CLI, the language server, the MCP server, the WebAssembly build and the serde_yaml shim each have their own tracker; the ecosystem page links to all six. A failing YAML document and the version you ran are the two things that make a report fast to act on.
Security reports
Please do not open a public issue for a security problem. The security policy gives a private address and says what to expect after you write.
Release notes
Every release is announced on the news page and in the RSS feed. There is no mailing list, so there is nothing to sign up for and nothing that collects your address.