Confidential comments on repository security advisories
You can now post confidential comments on repository security advisories that are visible only to people with write access to the repository, enabling secure discussion of vulnerability reports.
You can now post confidential comments on repository security advisories. Confidential comments are visible only to people with write access to the repository, so you can discuss a report with your team without the reporter or other invited collaborators seeing it.
Previously, every comment on an advisory was visible to all of its collaborators, including the reporter. To discuss suspected abuse, investigation details, or coordination notes, you had to move the conversation somewhere else and lose it from the advisory’s history.
With this update:
- Select Confidential. Only maintainers will see this comment below the comment box before you post.
- Confidential comments are clearly marked in the advisory timeline.
- Reporters and invited collaborators without write access can’t see confidential comments and aren’t notified about them.
- Access follows current repository permissions. If someone loses write access, they can no longer read confidential comments.
- Views of confidential comments are recorded in the audit log.
You can’t switch a comment between confidential and regular after you post it. Confidential comments are available in the GraphQL API, but they aren’t returned by the REST API.
This is available for public repositories with private vulnerability reporting enabled on GitHub Free, GitHub Pro, GitHub Team, and GitHub Enterprise Cloud.
Learn more about repository security advisories.
The post Confidential comments on repository security advisories appeared first on The GitHub Blog.
Source: original entry ↗
More from GitHub
Follow GitHub to get its new changes in your feed and email digest.
Claude Haiku 5.5 now available in GitHub Copilot
Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.
Purpose-built model for leaked secret detection
GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.
Local sandboxing for GitHub Copilot now generally available
GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.