Skip to content
GitHub Introduces Structured Forms for Private Vulnerability Reporting

GitHub Introduces Structured Forms for Private Vulnerability Reporting

First seen 1 Oct 2026, 22:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 23:15 UTC
  • •GitHub now requires structured forms for private vulnerability reports.
  • •Reporters must fill in four mandatory fields to enhance report quality.
  • •The feature is available for public repositories with private vulnerability reporting enabled.

On October 1, 2026, GitHub announced the implementation of structured forms for private vulnerability reports. This new feature aims to enhance the quality of vulnerability submissions by requiring reporters to fill out four mandatory fields: summary, details, proof of concept, and impact. The structured form is designed to reduce low-quality or AI-generated reports, making it easier for maintainers to assess vulnerabilities. Reporters can also disclose if they used AI assistance in their submissions. This feature is available for public repositories with private vulnerability reporting enabled across various GitHub plans, including GitHub Free, Pro, Team, and Enterprise Cloud. Additionally, repository owners can customize the form to suit their needs, ensuring that submissions meet specific criteria before acceptance.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
Structured forms launched
GitHub introduced structured forms for private vulnerability reports to improve submission quality.
Github.Blog

More articles in this cluster (3)

Common questions

What are the mandatory fields for the new vulnerability report?
Reporters must provide a summary, details, proof of concept, and impact.
Can I use AI assistance when reporting vulnerabilities?
Yes, reporters can disclose if they used AI assistance in their submissions.
Is this feature available for all GitHub users?
The structured forms are available for public repositories with private vulnerability reporting enabled on various GitHub plans.