To give security researchers a private reporting route, enable GitHub’s Private vulnerability reporting for an eligible public repository. On GitHub.com, open the repository and go to Settings → Security and quality → Advanced Security; switch on the control beside Private vulnerability reporting. Researchers can then use Report a vulnerability from the repository’s Advisories page.
Check that the repository is eligible
GitHub documents private vulnerability reporting for public repositories on GitHub.com. Repository owners and administrators can enable it. The roles GitHub lists for configuring the repository feature also include organization owners and security managers. If the repository is private, or you do not have an authorized role, the setting may not be available. See GitHub’s eligibility and configuration guidance.
Enable private vulnerability reporting
-
Open the public repository on GitHub.com.
-
Select Settings.
-
Under Security and quality, select Advanced Security.
-
Use the control beside Private vulnerability reporting to enable the feature.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
GitHub’s documented navigation labels are the ones above; interface wording can change. After enabling the feature, researchers can find Report a vulnerability on the repository’s Advisories page.
What a researcher will do
Anyone can privately report a vulnerability to maintainers of a public repository where the feature is enabled. The researcher opens the repository’s Security and quality area, chooses Report a vulnerability, reviews any security policy shown, completes the report form, and submits it.
Rank #2
GitHub’s default form asks for a summary, details, proof of concept, and impact statement. A reporter may also choose to disclose whether AI assistance was used to prepare the report. GitHub automatically adds the reporter as a collaborator and credited user on the proposed advisory. A reporter may optionally start a temporary private fork to work on a fix; only the maintainer can merge changes from that fork into the parent repository. Details are in GitHub’s private reporting documentation.
Customize the report form if needed
To change what the form asks reporters to provide, add VULNERABILITY_REPORT.yml or VULNERABILITY_REPORT.yaml to the repository’s .github directory. An organization or personal account can also define a default form in its .github repository. GitHub says an invalid or malformed custom form falls back to the default form.
Rank #3
A repository can require reporters to assign at least one CWE. That requirement applies to reports submitted through the web interface and REST API; it does not apply to maintainer-created advisories or edits to existing reports. See GitHub’s form customization instructions.
Make sure reports reach the right maintainers
Enabling the feature does not by itself guarantee that every maintainer will receive an email. GitHub’s notification guidance says administrators and security managers are notified when they watch all activity or subscribe to Security alerts and have notifications enabled for that repository. For email delivery, they must also select email notifications in their account notification settings. Review the relevant GitHub notification settings guidance.
Rank #4
When a report arrives, maintainers can accept it, ask for more information, or reject it. Accepting a report can turn it into a draft advisory for private collaboration; GitHub’s response and triage process is described in its repository security advisory guidance.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Use SECURITY.md if the private form is unavailable
SECURITY.md and private vulnerability reporting are separate. If the feature is unavailable or not enabled, GitHub directs researchers to follow the repository’s security policy or ask maintainers for their preferred security contact. The policy can name supported versions and explain how to report a vulnerability, but it does not create GitHub’s private reporting form. Maintainers can create SECURITY.md through the repository’s Security and quality area. See GitHub’s instructions for adding a security policy.
Best Value
| Route | When to use it | What it provides |
|---|---|---|
| Private vulnerability reporting | The public repository is on GitHub.com and the feature is enabled. | A structured private reporting route within GitHub. |
Contact route in SECURITY.md |
The feature is not enabled or is unavailable, or maintainers specify another contact method. | Reporting instructions and the contact route chosen by maintainers; it does not itself create a GitHub private report form. |
What happens before public disclosure
GitHub repository security advisories support private discussion and work on a fix before an advisory is published to inform the community after a patch is released. Private reporting and repository security advisories are documented for public repositories on GitHub.com. The private channel is therefore part of a coordinated disclosure workflow, not a public issue or an automatic promise that a report will be published immediately. See GitHub’s overview of repository security advisories.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




