GitHub now lets maintainers post confidential comments inside repository security advisories. Reading them requires write access, so an outside reporter or invited participant without that permission cannot see them. Authors choose confidentiality before posting and cannot switch a comment's visibility afterwards. Access follows current repository permissions, and views are recorded in audit logs.
Artificial Intelligence··Morning
Write permission defines the confidential audience
GitHub introduced confidential comments on repository security advisories, the discussions used to coordinate handling of software vulnerabilities. Only people with write access to the code repository can read them. A vulnerability reporter or invited participant without that permission cannot see a confidential comment or receive its notification.[1], [2]
Previously, every collaborator on an advisory could read its comments. Some internal discussions therefore moved to separate communication channels. The new option places those narrower discussions inside the advisory's existing timeline.[1]
Confidentiality is selected before posting
The author enables confidentiality before submitting a comment, and the discussion marks its visibility. Once posted, a comment cannot be converted between regular and confidential status. Ordinary comments remain available for conversations shared with outside participants, alongside the restricted internal entries.[1]
Access follows repository permissions
Removing someone's write permission also removes access to confidential comments. Views are recorded in audit logs. GitHub offers the feature in public repositories with private vulnerability reporting enabled on its Free, Pro, Team and Enterprise Cloud plans. The announcement describes support through the GraphQL application programming interface, which lets software request selected data from GitHub.[1]