# Confidential comments on repository security advisories

By Steven Van · 2026-10-02

Only people with write access can read them, and the comments are available on Free, Pro, Team and Enterprise Cloud for public repos.

Repository security advisories now support confidential comments, which only people with write access to the repository can read. Maintainers can discuss a report without the reporter or other invited collaborators seeing it. Until now, every comment on an advisory was visible to all of its collaborators, including the reporter, so talk about suspected abuse, investigation details or coordination notes had to move elsewhere and dropped out of the advisory's history.

[GitHub](<https://creatorstoolbox.com/tools/github>) describes how it works in its [repository security advisories documentation](<https://docs.github.com/code-security/concepts/vulnerability-reporting-and-management/repository-security-advisories>):

- Selecting **Confidential** shows a note below the comment box that only maintainers will see the comment.

- Confidential comments are clearly marked in the advisory timeline.

- Reporters and invited collaborators without write access can't see them and aren't notified about them.

- Access follows current repository permissions, so someone who loses write access can no longer read them.

- Views of confidential comments are recorded in the audit log.

- A comment can't be switched between confidential and regular after it is posted.

- Confidential comments are available in the GraphQL API but aren't returned by the REST API.

The feature is available for public repositories with private vulnerability reporting enabled, on GitHub Free, GitHub Pro, GitHub Team and GitHub Enterprise Cloud.

![GitHub](<https://github.githubassets.com/assets/GitHub-Mark-ea2971cee799.png>)

GitHub

Where the world builds software — Git hosting, pull requests, issues, Actions CI/CD, and Copilot, free for public and private repos.

[View GitHub →](<https://creatorstoolbox.com/tools/github>)

[Original source](<https://docs.github.com/code-security/concepts/vulnerability-reporting-and-management/repository-security-advisories>)

[Read Confidential comments on repository security advisories on Creators Toolbox](<https://creatorstoolbox.com/blog/github-confidential-comments-on-repository-security-advisories>)

---
Canonical source: https://creatorstoolbox.com/blog/github-confidential-comments-on-repository-security-advisories
