GitHub Adds Confidential Comments for Repository Security Advisories

AI Tech Team
•
October 4, 2026
•
👁️ 8 views
🖼️ Featured Image / Generated Result
GitHub Adds Confidential Comments for Repository Security Advisories

GitHub added confidential comments to repository security advisories on October 2, 2026. The feature lets people with write access discuss sensitive security information without exposing those comments to reporters or invited collaborators who lack write permission.

What changed

When writing a comment on an eligible advisory, maintainers can select Confidential. The comment is clearly marked in the advisory timeline and is visible only to users with write access to the repository. GitHub also records views of confidential comments in the audit log.

Why this is useful

Security investigations frequently involve details that should not be shared with every participant. Maintainers may need to discuss suspected abuse, exploitability, internal remediation steps, or coordination plans before publishing broader information.

How it fits security workflows

Previously, teams that needed private discussion often had to move the conversation to another system. That created a split between the advisory record and the sensitive investigation context. Confidential comments keep that part of the discussion closer to the advisory while preserving access boundaries.

API limitation

GitHub says confidential comments are available through the GraphQL API but are not returned by the REST API. This distinction matters for security integrations that export or synchronize advisory discussions.

Practical takeaway

Security teams should define clearly which information belongs in public, collaborator-visible, and confidential advisory comments. Use confidential comments for sensitive operational details, and do not build REST-based exports that assume they contain the complete advisory conversation.

Source: GitHub Changelog — Confidential comments

← Back to all articles