Github.Blog New API Features Enhance Repository Security Advisory Management
Article Content
- •New API allows management of repository security advisories.
- •Confidential comments can be posted, enhancing privacy for sensitive discussions.
- •Access to features follows existing repository permissions.
GitHub has introduced new features in its API for managing repository security advisories, allowing users to read, add, and edit comments on advisories created from private vulnerability reports. This update aims to improve the triage context available for vulnerabilities, which was previously only accessible via the web UI. The new API endpoints enable users to list comments, view advisory responses, and export discussions for audits. Access to these features is governed by existing repository permissions, ensuring that only authorized users can view or interact with the advisories. Confidential comments can now be posted, visible only to those with write access, enhancing privacy for sensitive discussions. These updates are available in public preview for various GitHub plans, including GitHub Free and GitHub Enterprise Cloud.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What new features were introduced for repository security advisories?
Who can see confidential comments on advisories?
Are there any security vulnerabilities associated with these updates?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…