DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk3 min

How to Set Up Private Vulnerability Reporting on GitHub

A practical guide to enabling GitHub’s private vulnerability report form, setting maintainer notifications, and providing a SECURITY.md fallback.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To give security researchers a private reporting route, enable GitHub’s Private vulnerability reporting for an eligible public repository. On GitHub.com, open the repository and go to Settings → Security and quality → Advanced Security; switch on the control beside Private vulnerability reporting. Researchers can then use Report a vulnerability from the repository’s Advisories page.

Check that the repository is eligible

GitHub documents private vulnerability reporting for public repositories on GitHub.com. Repository owners and administrators can enable it. The roles GitHub lists for configuring the repository feature also include organization owners and security managers. If the repository is private, or you do not have an authorized role, the setting may not be available. See GitHub’s eligibility and configuration guidance.

Enable private vulnerability reporting

  1. Open the public repository on GitHub.com.

  2. Select Settings.

  3. Under Security and quality, select Advanced Security.

  4. Use the control beside Private vulnerability reporting to enable the feature.

    What’s actually slowing this PC down?

    Pick the symptom - the matching free tool is one click away.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GitHub’s documented navigation labels are the ones above; interface wording can change. After enabling the feature, researchers can find Report a vulnerability on the repository’s Advisories page.

What a researcher will do

Anyone can privately report a vulnerability to maintainers of a public repository where the feature is enabled. The researcher opens the repository’s Security and quality area, chooses Report a vulnerability, reviews any security policy shown, completes the report form, and submits it.

GitHub’s default form asks for a summary, details, proof of concept, and impact statement. A reporter may also choose to disclose whether AI assistance was used to prepare the report. GitHub automatically adds the reporter as a collaborator and credited user on the proposed advisory. A reporter may optionally start a temporary private fork to work on a fix; only the maintainer can merge changes from that fork into the parent repository. Details are in GitHub’s private reporting documentation.

Customize the report form if needed

To change what the form asks reporters to provide, add VULNERABILITY_REPORT.yml or VULNERABILITY_REPORT.yaml to the repository’s .github directory. An organization or personal account can also define a default form in its .github repository. GitHub says an invalid or malformed custom form falls back to the default form.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A repository can require reporters to assign at least one CWE. That requirement applies to reports submitted through the web interface and REST API; it does not apply to maintainer-created advisories or edits to existing reports. See GitHub’s form customization instructions.

Make sure reports reach the right maintainers

Enabling the feature does not by itself guarantee that every maintainer will receive an email. GitHub’s notification guidance says administrators and security managers are notified when they watch all activity or subscribe to Security alerts and have notifications enabled for that repository. For email delivery, they must also select email notifications in their account notification settings. Review the relevant GitHub notification settings guidance.

When a report arrives, maintainers can accept it, ask for more information, or reject it. Accepting a report can turn it into a draft advisory for private collaboration; GitHub’s response and triage process is described in its repository security advisory guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use SECURITY.md if the private form is unavailable

SECURITY.md and private vulnerability reporting are separate. If the feature is unavailable or not enabled, GitHub directs researchers to follow the repository’s security policy or ask maintainers for their preferred security contact. The policy can name supported versions and explain how to report a vulnerability, but it does not create GitHub’s private reporting form. Maintainers can create SECURITY.md through the repository’s Security and quality area. See GitHub’s instructions for adding a security policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Route When to use it What it provides
Private vulnerability reporting The public repository is on GitHub.com and the feature is enabled. A structured private reporting route within GitHub.
Contact route in SECURITY.md The feature is not enabled or is unavailable, or maintainers specify another contact method. Reporting instructions and the contact route chosen by maintainers; it does not itself create a GitHub private report form.

What happens before public disclosure

GitHub repository security advisories support private discussion and work on a fix before an advisory is published to inform the community after a patch is released. Private reporting and repository security advisories are documented for public repositories on GitHub.com. The private channel is therefore part of a coordinated disclosure workflow, not a public issue or an automatic promise that a report will be published immediately. See GitHub’s overview of repository security advisories.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.