GitHub Security Lab reposted this
For years, I've argued about how hard it is for open source maintainers to handle security reports. Today I want to give credit where it's due: GitHub just shipped a whole batch of updates to private vulnerability reporting and security advisories, and it directly addresses the pain points maintainers have been raising for a while. In two days, they landed: 1. Structured forms for private vulnerability reports. No more anonymous free-text dumps. Reporters now fill in summary, details, proof of concept (minimum 150 characters), and impact. You can customize the form with a `.github/VULNERABILITY_REPORT.yml` file, require a CWE assignment, and even let reporters disclose that they used AI assistance. Anyone who has triaged a flood of low-quality or AI-generated reports knows how much this helps separate signal from noise. 2. Rate limits for private vulnerability reports. Bulk and automated submissions were burying the reports that actually mattered. Daily per-user caps, a custom repo limit, and an allow list for trusted reporters mean legitimate researchers still reach you while the spam gets throttled. 3. Confidential comments on repository security advisories. This one is personal for me. You can now post comments visible only to maintainers, so you can discuss abuse, investigation details, and coordination without the reporter seeing everything. It's marked in the timeline, follows repository permissions, and is audit-logged. No more moving sensitive discussion to another tool and losing it from the advisory's history. 4. A REST API for advisory comments, in public preview. The triage discussion used to live only in the web UI. Now you can list, get, add, and edit comments programmatically, plus see comment counts on advisory responses. Now I can fully automate my response flow... to fight the horde. 5. New fields in the SecurityAdvisory GraphQL API: `cveId`, `sourceCodeLocation`, `githubReviewedAt`, `nvdPublishedAt`, and `repositoryAdvisoryUrl`, plus `severities` and `isWithdrawn` filters. Fewer round trips, one authentication path, one rate limit budget for integrations. Severity-based triage feeds and tracking how fast advisories move from NVD to GitHub review just got much easier. You know that I'm not one to hand out praise lightly: I've spent my share of time complaining about the incentive structures around security in open source. But this batch of changes is thoughtful and maintainer-first. It makes reporting better structured, the inbox saner, and the private coordination we need actually possible. Thank you, GitHub. This is exactly the kind of investment in the OSS security ecosystem that matters. If you maintain a public repository, enable private vulnerability reporting and give these a spin.