GitHub has introduced confidential comments for repository security advisories, enabling maintainers to discuss reports privately within the advisory timeline.
WHAT CHANGED WITH CONFIDENTIAL COMMENTS
Confidential comments are visible only to people with write access to the repository. TechStaged has also covered GitHub opens REST API for repository security advisory comments in public preview.
Previously, every comment on an advisory was visible to all collaborators, including reporters.
Confidential comments can be used to discuss suspected abuse, investigation details, or coordination notes without exposing them to reporters.
HOW IT WORKS
Only maintainers will see a confidential comment below the comment box before you post.
Confidential comments are clearly marked in the advisory timeline.
Reporters and invited collaborators without write access cannot see confidential comments and aren’t notified about them.
Access follows current repository permissions.
Views of confidential comments are recorded in the audit log.
Confidential comments are available in the GraphQL API, but they aren’t returned by the REST API.
This feature is available for public repositories with private vulnerability reporting enabled on GitHub Free, GitHub Pro, GitHub Team, and GitHub Enterprise Cloud.
WHY IT MATTERS
This feature lets teams discuss suspected abuse, investigation details, or coordination notes privately within the advisory, without exposing those conversations to reporters or invited collaborators lacking write access.
It preserves the advisory’s history while enabling private discussions among authorized contributors.
NEXT STEPS AND AVAILABILITY
For public repositories with private vulnerability reporting enabled, confidential comments are available on GitHub’s advisory workflow.
Developers should note that confidential comments appear via GraphQL and are not returned by the REST API.
For more details, refer to the GitHub Changelog entry on confidential comments on repository security advisories.
RELATED COVERAGE
- GitHub opens REST API for repository security advisory comments in public preview
- GitHub expands SecurityAdvisory GraphQL API with five new fields and two filters
- GitHub completes staged rollout of stateless App installation tokens, with longer token format and unchanged permissions
- GitHub posits AI is reshaping developer work, urges three skills to sharpen
- Developer Tools articles
SOURCES
- Archive: 2026 - GitHub Changelog: Confidential comments on repository security advisories Published · Primary source



