# Confidential comments on repository security advisories

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: GitHub Changelog
- Author credit: Allison
- Category: Cyber
- Original publication time: 2026-10-02T13:15:40Z
- First observed by NexusTechWire: 2026-10-02T14:50:46Z
- Original source: https://github.blog/changelog/2026-10-02-confidential-comments-on-repository-security-advisories
- NexusTechWire record: https://nexustechwire.com/news/news-59fc4a70abc335f98eb4

## The brief

GitHub now lets repository teams discuss vulnerability reports inside security advisories using comments restricted to users who currently have write access. Reporters and invited collaborators lacking that permission cannot read them or receive notifications; losing write access also removes visibility. Comment visibility cannot be changed after posting. GitHub says the feature covers public repositories with private vulnerability reporting enabled across its Free, Pro, Team and Enterprise Cloud plans.

AI-assisted NexusTechWire summary, checked against the linked source on 2026-10-02T15:02:37Z. Not independent reporting.

Read the full original: [GitHub Changelog](https://github.blog/changelog/2026-10-02-confidential-comments-on-repository-security-advisories)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
