Skip to content
GitHub Implements Daily Rate Limits on Private Vulnerability Reports

GitHub Implements Daily Rate Limits on Private Vulnerability Reports

First seen 6 Oct 2026, 00:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 02:26 UTC
  • •GitHub has introduced daily rate limits on private vulnerability reports.
  • •The limits are designed to reduce low-quality and automated submissions.
  • •Repository administrators can customize reporting limits and allow-list trusted researchers.

GitHub has announced the introduction of daily rate limits on private vulnerability reports to combat the increasing volume of low-quality and automated submissions. These limits apply both to individual repositories and across the platform, though specific thresholds have not been disclosed. Repository administrators can set custom limits and allow-list trusted researchers to bypass these restrictions. The changes aim to alleviate the burden on open-source maintainers, who are overwhelmed by reports that obscure vulnerabilities. GitHub stated that the new limits will not affect existing bug reports, allowing ongoing investigations into previously submitted advisories. The decision reflects a growing concern over the scalability of traditional security-disclosure workflows in the face of AI-generated reports. This initiative is available for public repositories with Private Vulnerability Reporting enabled on GitHub Free, Pro, Team, and Enterprise Cloud.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
GitHub announces rate limits for vulnerability reports
GitHub revealed new daily rate limits for private vulnerability reports to combat low-quality submissions.
Github.Blog
2026-10-05
DevOps article discusses GitHub's new limits
An article elaborated on GitHub's implementation of rate limits, emphasizing the challenges faced by open-source maintainers.
Devops

More articles in this cluster (2)

Common questions

What are the new rate limits?
GitHub has not disclosed the specific thresholds for the daily rate limits on private vulnerability reports.
Can repository administrators customize limits?
Yes, repository administrators can set custom reporting limits and allow-list trusted researchers.
Will existing reports be affected by these limits?
No, existing bug reports will remain accessible and unaffected by the new reporting limits.