# Structured forms for private vulnerability reports

By Steven Van · 2026-10-01

Public repos with private vulnerability reporting get four required fields by default, and maintainers can customize the form with a YAML file.

Private vulnerability reports on public GitHub repositories can now use a structured form instead of a single free-text box. GitHub says the free-text box made it easy to submit low-quality or AI-generated reports and hard for maintainers to find the useful ones. The change is described in the [GitHub docs](<https://docs.github.com/code-security/how-tos/report-and-fix-vulnerabilities/report-privately>), and it applies to [GitHub](<https://creatorstoolbox.com/tools/github>) repositories that have private vulnerability reporting enabled.

By default, reporters must fill in four required fields: summary, details, proof of concept (at least 150 characters) and impact. Their answers are combined into the advisory description, so maintainers review and edit the report as they do today.

- Maintainers can customize the form by adding a .github/VULNERABILITY\_REPORT.yml file to the default branch. Adding it to the .github repository of an organization or account applies it to every repository that owner has.

- Forms use issue form syntax, and fields support min\_length to require a minimum level of detail. An invalid form falls back to the default form.

- Maintainers can require reporters to assign a CWE before submitting, from Settings &gt; Advanced Security &gt; Private vulnerability reporting. Organization and enterprise owners can enforce this through a policy.

- If a repository has a security policy, reporters see a banner linking to its SECURITY.md before they submit.

- Reporters can tick a box to say they used AI assistance to find or write up the report.

A custom form also applies to reports submitted through the REST API, which must match it. The default form is not enforced for the API, so existing integrations keep working. When an API submission does not match, the error points to a new endpoint that returns the form the repository enforces.

The feature is available for public repositories with private vulnerability reporting enabled on **GitHub Free, Pro, Team and Enterprise Cloud**.

![Screenshot of the bottom of a security advisory. A button, labeled "Start a temporary fork" is outlined in dark orange.](<https://docs.github.com/assets/cb-51900/images/help/security/advisory-start-a-temporary-private-fork-button.png>)

Bottom of a security advisory with the "Start a temporary fork" button outlined

![GitHub](<https://github.githubassets.com/assets/GitHub-Mark-ea2971cee799.png>)

GitHub

Where the world builds software — Git hosting, pull requests, issues, Actions CI/CD, and Copilot, free for public and private repos.

[View GitHub →](<https://creatorstoolbox.com/tools/github>)

[Original source](<https://docs.github.com/code-security/how-tos/report-and-fix-vulnerabilities/report-privately>)

[Read Structured forms for private vulnerability reports on Creators Toolbox](<https://creatorstoolbox.com/blog/github-structured-forms-for-private-vulnerability-reports>)

---
Canonical source: https://creatorstoolbox.com/blog/github-structured-forms-for-private-vulnerability-reports
