What changes for security teams
Previously, advisory comments were visible to every collaborator, including the reporter. GitHub says sensitive investigation details, suspected-abuse discussions, and coordination notes therefore had to move elsewhere. Confidential comments keep those conversations in the advisory’s history.
The access rules are specific:
- Reporters and invited collaborators without write access cannot see confidential comments or receive notifications about them.
- Visibility follows current permissions: losing write access removes access to these comments.
- Comment views are recorded in the audit log.
- Confidential entries are marked in the advisory timeline.
The important distinction is permission, not job title. A reporter who also has repository write access is not excluded merely because they submitted the report. Teams should therefore treat their repository permissions as the audience boundary—not assume “confidential” means a handpicked subgroup. This is a practical implication of GitHub’s stated access model.
Check the audience before posting
Select Confidential below the comment box before posting. GitHub displays a maintainer-only visibility notice. Once posted, a comment cannot switch between confidential and regular.
For maintainers, the sensible workflow is to decide which audience needs the information before submitting it. Internal coordination and reporter-facing remediation discussion serve different purposes; keeping the former restricted should not make the latter disappear.
GitHub’s advisory documentation emphasizes collaboration between researchers and maintainers: privately discuss the vulnerability, develop and validate a fix, then publish information that helps users respond. Temporary private forks can support that remediation work. Confidential comments add an internal discussion channel to this process, rather than replacing coordinated disclosure.
Availability and automation limits
The feature is available for public repositories with private vulnerability reporting enabled on GitHub Free, Pro, Team, and Enterprise Cloud. Confidential comments are available through GraphQL but are not returned by REST.
That API split warrants attention from teams building advisory integrations: do not assume a REST-based record captures the confidential discussion. GitHub’s announcement does not specify query fields or audit-event names.
There is also a separate disclosure responsibility worth preserving. GitHub recommends including a fixed version before publishing an advisory whenever possible; otherwise, Dependabot can warn users without offering a safe version to update to. Better internal coordination is useful, but actionable remediation remains the outcome that matters to downstream developers and IT teams.
References
- Confidential comments on repository security advisories GitHub Changelog · 2026-10-02T13:15:40+00:00
- Repository security advisories - GitHub Docs docs.github.com
- Repository security advisories - GitHub Docs docs.github.com