Skip to main content

Working with repository security advisories

Discuss, fix, and disclose security vulnerabilities in your public repositories using repository security advisories.

Permission levels for repository security advisories

The actions you can take in a repository security advisory depend on whether you have admin or write permissions to the security advisory.

Configuring private vulnerability reporting for an organization

Organization owners and security managers can allow security researchers to report vulnerabilities securely in repositories within the organization by enabling private vulnerability reporting for all its public repositories.