Eigen RadarAI
Analysis

GitHub adds private discussions inside security advisories

GitHub now lets maintainers post confidential comments inside repository security advisories. Reading them requires write access, so an outside reporter or invited participant without that permission cannot see them. Authors choose confidentiality before posting and cannot switch a comment's visibility afterwards. Access follows current repository permissions, and views are recorded in audit logs.

Artificial Intelligence··Morning
A small privacy padlock in the corner of a blank comment panel on a laptop.

Write permission defines the confidential audience

GitHub introduced confidential comments on repository security advisories, the discussions used to coordinate handling of software vulnerabilities. Only people with write access to the code repository can read them. A vulnerability reporter or invited participant without that permission cannot see a confidential comment or receive its notification.[1], [2]

Previously, every collaborator on an advisory could read its comments. Some internal discussions therefore moved to separate communication channels. The new option places those narrower discussions inside the advisory's existing timeline.[1]

Confidentiality is selected before posting

The author enables confidentiality before submitting a comment, and the discussion marks its visibility. Once posted, a comment cannot be converted between regular and confidential status. Ordinary comments remain available for conversations shared with outside participants, alongside the restricted internal entries.[1]

Access follows repository permissions

Removing someone's write permission also removes access to confidential comments. Views are recorded in audit logs. GitHub offers the feature in public repositories with private vulnerability reporting enabled on its Free, Pro, Team and Enterprise Cloud plans. The announcement describes support through the GraphQL application programming interface, which lets software request selected data from GitHub.[1]

References

  1. News sourceGitHub ChangelogGitHub adds confidential comments to security advisories↩1↩2↩3↩4
  2. News sourceMikhbarGitHub limits confidential security-advisory comments to maintainers↩