Trending:

GitHub adds confidential comments to repository security advisories

Illustration of a GitHub security advisory timeline with a confidential tag
TechStaged-owned

Summary

  • Confidential comments on repository security advisories can be posted.
  • Confidential comments are visible only to people with write access to the repository.
  • Previously, every comment on an advisory was visible to all of its collaborators, including the reporter.

GitHub has introduced confidential comments for repository security advisories, enabling maintainers to discuss reports privately within the advisory timeline.

WHAT CHANGED WITH CONFIDENTIAL COMMENTS

Confidential comments are visible only to people with write access to the repository. TechStaged has also covered GitHub opens REST API for repository security advisory comments in public preview.

Previously, every comment on an advisory was visible to all collaborators, including reporters.

Confidential comments can be used to discuss suspected abuse, investigation details, or coordination notes without exposing them to reporters.

HOW IT WORKS

Only maintainers will see a confidential comment below the comment box before you post.

Confidential comments are clearly marked in the advisory timeline.

Reporters and invited collaborators without write access cannot see confidential comments and aren’t notified about them.

Access follows current repository permissions.

Views of confidential comments are recorded in the audit log.

Confidential comments are available in the GraphQL API, but they aren’t returned by the REST API.

This feature is available for public repositories with private vulnerability reporting enabled on GitHub Free, GitHub Pro, GitHub Team, and GitHub Enterprise Cloud.

WHY IT MATTERS

This feature lets teams discuss suspected abuse, investigation details, or coordination notes privately within the advisory, without exposing those conversations to reporters or invited collaborators lacking write access.

It preserves the advisory’s history while enabling private discussions among authorized contributors.

NEXT STEPS AND AVAILABILITY

For public repositories with private vulnerability reporting enabled, confidential comments are available on GitHub’s advisory workflow.

Developers should note that confidential comments appear via GraphQL and are not returned by the REST API.

For more details, refer to the GitHub Changelog entry on confidential comments on repository security advisories.

Reporting by Owen Blackridge; editing by TechStaged editors

Editorial disclosure: This article was prepared with AI assistance from a source-limited research package and passed TechStaged's automated factual, originality, licensing, and publication checks.

Our Standards: The TechStaged Editorial Principles.

f in

Owen Blackridge

Owen Blackridge

Technology Editor

Owen covers platform shifts, AI launches, and the practical impact of emerging technology on small teams.