megachangelog
Announcement

Rate limits for private vulnerability reports

Rate limits now cap how many new vulnerability reports a single account can submit, helping maintainers avoid being overwhelmed by low-quality and automated reports.

Open source maintainers are receiving more low-quality and automated vulnerability reports, which can bury the reports that matter. Rate limits cap how many new reports a single account can submit in a day, both to your repository and across GitHub. This helps protect you from bulk and automated submissions, while legitimate researchers can still reach you.

With this update:

  • Private vulnerability reporting now applies daily per-user rate limits to new reports.
  • Reporters who reach a limit see a message asking them to try again later.
  • Limits apply only to new reports. Comments on existing advisories aren’t affected.
  • Repository administrators can set a custom daily overall reporting limit for their repository.
  • Repository administrators can add trusted reporters to an allow list so they’re never rate limited.

To configure these settings, go to your repository’s settings, select Advanced Security, and click Settings next to “Private vulnerability reporting.”

This is available for public repositories with private vulnerability reporting enabled on GitHub Free, GitHub Pro, GitHub Team, and GitHub Enterprise Cloud.

Learn more in our docs about configuring private vulnerability reporting.

The post Rate limits for private vulnerability reports appeared first on The GitHub Blog.

securityvulnerabilityapirate-limits

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →