Skip to main content

Repository security advisory comments API in public preview

By Steven Van ·

Advisory discussions, including those from private vulnerability reports, can now be listed, added and edited via REST on public repos in public preview.

GitHub now lets you read, add and edit comments on repository security advisories through the REST API, including advisories created from private vulnerability reports. Until now, that discussion, which often holds the most useful GitHub triage context, could only be reached in the web UI. The new endpoints are in public preview.

  • List the comments on an advisory, optionally limited to those updated since a given time.
  • Get a single comment.
  • Add a comment.
  • Edit a comment.

Repository security advisory responses now include a comments count, and global advisory responses include the count for their linked repository advisory. The counts cover non-confidential comments only, so you can tell which advisories have discussion before fetching it. GitHub says this supports exporting advisory discussions for audits and migrations, adding triage notes automatically, and building advisory workflows that work like the ones for issues and pull requests.

Access follows the rules of the advisory itself. Callers need permission to view the advisory and the appropriate read or write repository security advisories permission or token scope. Non-collaborators cannot see internal comments, and confidential comments are not returned by these endpoints. Deleting comments is not supported through the API yet.

The preview covers public repositories on GitHub Free, Pro, Team and Enterprise Cloud.

GitHub
GitHub
Where the world builds software — Git hosting, pull requests, issues, Actions CI/CD, and Copilot, free for public and private repos.
View GitHub →

Original source

Read Repository security advisory comments API in public preview on Creators Toolbox