
GitHub opens security advisory comments to REST API workflows
GitHub's public preview lets security teams read and write repository advisory comments through the REST API.
GitHub has opened a new REST API path for comments on repository security advisories, giving maintainers and security teams a way to move advisory discussion into the same automated workflows they already use for issues, pull requests, audits, and migrations.
The public preview covers comments on repository security advisories, including advisories created from private vulnerability reports. GitHub says teams can list comments, fetch a single comment, add a comment, and edit a comment through the API. The list endpoint can also be limited to comments updated since a given time, which matters for teams that sync advisory activity into ticketing systems or compliance archives instead of polling an entire conversation every time.
What changed
Until now, GitHub said the discussion attached to an advisory was available only in the web interface, even though that thread often contains the working context for triage. That context can include reproduction notes, maintainer decisions, coordination steps, and explanations for why a vulnerability report was accepted, delayed, or closed. Moving those comments into REST endpoints makes the advisory record less isolated from the rest of an organization's security operations.
GitHub also added a comments count to repository security advisory responses. Global advisory responses can include the count for a linked repository advisory. The count covers non-confidential comments, which lets integrations decide whether there is discussion to fetch before making another request.
Why it matters
For small open source maintainers, the change is mostly about convenience. For larger engineering organizations, it can close an awkward gap in evidence collection. Security teams often need to show how a reported issue was investigated, who responded, and what changed before disclosure. If advisory comments stay trapped in a browser workflow, audit trails become manual screenshots, copied notes, or partial exports.
The practical CyberOGZ read is that GitHub is turning repository advisories into a more automation-friendly object, not just a disclosure page. That helps teams standardize vulnerability intake, but it also increases the value of access controls around advisory scopes. GitHub says access follows the advisory itself, requires the repository security advisories permission or token scope, excludes non-collaborators from internal comments, and does not return confidential comments through these REST endpoints.
- Available now in public preview for public repositories on GitHub Free, Pro, Team, and Enterprise Cloud.
- Supported actions include listing, reading, adding, and editing comments.
- Deleting comments is not supported through the API yet.
The next thing to watch is whether teams fold this into disclosure pipelines carefully. API access can reduce blind spots, but only if tokens are scoped narrowly and automated notes are written with the same care as public advisory text.
Sources
Cover photo by Syirwan Ainu on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment