GitHub’s Confidential Advisory Comments Follow Repository Write Access
On 2 October 2026, GitHub added confidential comments to repository security advisories. Reporters and invited collaborators without write access cannot read the comments or receive notifications; repository writers can.
Access ends when write permission is removed. A posted comment cannot switch between confidential and ordinary. Views are logged.
Check the audience and the archive
BlackTree analysis: Review repository writers before adding sensitive notes. If the group is too broad, use a narrower channel.
GraphQL includes confidential comments; REST omits them. Check whether a REST-based case archive is missing internal context.
This applies to public repositories with private vulnerability reporting enabled on Free, Pro, Team and Enterprise Cloud. GitHub’s advisory workflow supports private fix coordination before disclosure.
Keep the shared report usable
An advisory is also where maintainers and a reporter work through impact and a fix before publication. BlackTree analysis: Keep decisions the reporter needs in that shared conversation. Separate sensitive internal assessment from the explanation of what will be repaired and disclosed. A later reviewer should be able to understand both the private coordination and the outward decision.


