Skip to main content

Rate limits for private vulnerability reports

By Steven Van ·

Daily per-user limits apply to new private vulnerability reports on public repositories, and admins can set their own cap and an allow list.

Private vulnerability reporting on GitHub now applies daily per-user rate limits to new reports, according to GitHub. The limits cap how many new reports a single account can submit in a day, both to one repository and across GitHub. GitHub says the aim is to protect open source maintainers from bulk and automated submissions that can bury the reports that matter.

  • Reporters who hit a limit see a message asking them to try again later.
  • Limits apply only to new reports. Comments on existing advisories are not affected.
  • Repository administrators can set a custom daily overall reporting limit for their repository.
  • Repository administrators can add trusted reporters to an allow list so they are never rate limited.

To configure these settings, open the repository's settings, select Advanced Security, and click Settings next to "Private vulnerability reporting". The feature is available for public repositories with private vulnerability reporting enabled, on GitHub Free, Pro, Team and Enterprise Cloud.

GitHub
GitHub
Where the world builds software — Git hosting, pull requests, issues, Actions CI/CD, and Copilot, free for public and private repos.
View GitHub →

Original source

Read Rate limits for private vulnerability reports on Creators Toolbox