Skip to content
New API Features Enhance Repository Security Advisory Management

New API Features Enhance Repository Security Advisory Management

First seen 4 Oct 2026, 05:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •New API allows management of repository security advisories.
  • •Confidential comments can be posted, enhancing privacy for sensitive discussions.
  • •Access to features follows existing repository permissions.

GitHub has introduced new features in its API for managing repository security advisories, allowing users to read, add, and edit comments on advisories created from private vulnerability reports. This update aims to improve the triage context available for vulnerabilities, which was previously only accessible via the web UI. The new API endpoints enable users to list comments, view advisory responses, and export discussions for audits. Access to these features is governed by existing repository permissions, ensuring that only authorized users can view or interact with the advisories. Confidential comments can now be posted, visible only to those with write access, enhancing privacy for sensitive discussions. These updates are available in public preview for various GitHub plans, including GitHub Free and GitHub Enterprise Cloud.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-02
Repository security advisory comments API introduced
GitHub launched a public preview of its new API features for managing repository security advisories, including listing and editing comments.
Github.Blog
2026-10-02
Confidential comments feature launched
GitHub introduced the ability to post confidential comments on repository security advisories, visible only to users with write access.
Github.Blog

More articles in this cluster (2)

Common questions

What new features were introduced for repository security advisories?
GitHub introduced an API for managing advisories, allowing users to read, add, and edit comments.
Who can see confidential comments on advisories?
Confidential comments are visible only to users with write access to the repository.
Are there any security vulnerabilities associated with these updates?
The articles do not mention any vulnerabilities; these are new features aimed at enhancing advisory management.