Skip to content

Commit e85b503

Browse files
sophiethekingCopilotlecoursen
authored
Structured, required proof-of-concept fields + Confidential team-only comments for private vulnerability reports (#63552)
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Laura Coursen <lecoursen@github.com>
1 parent 612c08d commit e85b503

9 files changed

Lines changed: 91 additions & 9 deletions

File tree

‎content/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configure-for-a-repository.md‎

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,56 @@ The instructions in this article refer to enablement at repository level. For in
3131

3232
{% data reusables.security-advisory.private-vulnerability-api %}
3333

34+
## Customizing the vulnerability reporting form
35+
36+
By default, the private vulnerability reporting form requires reporters to provide a summary, details, proof of concept, and impact statement. This structured information helps maintainers assess reports consistently and reduces the need to request missing details.
37+
38+
To customize the form, add a `VULNERABILITY_REPORT.yml` or `VULNERABILITY_REPORT.yaml` file to the repository's `.github` directory. You can also define a default form for an organization or personal account in the `.github` repository owned by that account. A form in an individual repository takes precedence over the form in the owner's `.github` repository.
39+
40+
Private vulnerability reporting forms use the same YAML syntax as issue forms. The forms support `checkboxes`, `dropdown`, `input`, `markdown`, and `textarea` elements. You can mark fields as required and use `min_length` to require a minimum number of characters for `input` and `textarea` elements. For information about the supported keys for each element, see [AUTOTITLE](/communities/using-templates-to-encourage-useful-issues-and-pull-requests/syntax-for-githubs-form-schema).
41+
42+
For example, the following form requires a detailed proof of concept of at least 100 characters.
43+
44+
```yaml copy
45+
name: Private vulnerability report
46+
description: Provide the information maintainers need to assess the report.
47+
body:
48+
- type: textarea
49+
id: summary
50+
attributes:
51+
label: Summary
52+
description: Summarize the vulnerability and its potential severity.
53+
validations:
54+
required: true
55+
- type: textarea
56+
id: proof_of_concept
57+
attributes:
58+
label: Proof of concept
59+
description: Provide complete instructions for reproducing the vulnerability.
60+
validations:
61+
required: true
62+
min_length: 100
63+
- type: textarea
64+
id: impact
65+
attributes:
66+
label: Impact
67+
description: Explain who is affected and how.
68+
validations:
69+
required: true
70+
```
71+
72+
If {% data variables.product.prodname_dotcom %} cannot parse or validate a custom form, reporters see the default form instead.
73+
74+
## Requiring reporters to assign a CWE
75+
76+
You can require reporters to associate at least one Common Weakness Enumeration (CWE) with each new report. This repository-level setting applies to reports submitted in the web interface and with the REST API. It does not apply to repository maintainers who create advisories or to edits of existing reports.
77+
78+
{% data reusables.repositories.navigate-to-repo %}
79+
{% data reusables.repositories.sidebar-settings %}
80+
{% data reusables.repositories.navigate-to-code-security-and-analysis %}
81+
1. Under **{% data variables.product.UI_advanced_security %}**, to the right of **Private vulnerability reporting**, click **Settings**.
82+
1. Under **Submission requirements**, enable **Require a CWE assignment**.
83+
3484
## Configuring notifications for private vulnerability reporting
3585
3686
{% data reusables.security-advisory.private-vulnerability-reporting-configure-notifications %}

‎content/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/manage-vulnerability-reports.md‎

Lines changed: 16 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,20 +21,34 @@ When a security researcher reports a vulnerability privately, you are notified a
2121

2222
For more information about configuring notification preferences, see [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configure-for-a-repository#configuring-notifications-for-private-vulnerability-reporting).
2323

24+
## Reviewing a vulnerability report
25+
2426
{% data reusables.repositories.navigate-to-repo %}
2527
{% data reusables.repositories.sidebar-security %}
2628
{% data reusables.repositories.sidebar-advisories %}
2729
1. Click the advisory you want to review. An advisory that was reported privately has a status of `Triage`.
2830

2931
![Screenshot of a "Security Advisories" list.](/assets/images/help/security/advisory-list.png)
3032

31-
1. Carefully review the report, then choose how to proceed.
33+
1. Carefully review the report details and any disclosure of AI assistance. Then choose how to proceed.
3234
* To collaborate on a patch in private, click **Start a temporary private fork** to create a place for further discussions with the contributor. This does not change the status of the proposed advisory from `Triage`.
3335
* To accept the reported vulnerability, click **Accept and open as draft** to accept the vulnerability report as a draft advisory on {% data variables.product.prodname_dotcom %}. If you choose this option:
3436
* This doesn't make the report public.
3537
* The report becomes a draft repository security advisory and you can work on it in the same way as any draft advisory that you create.
3638
For more information on security advisories, see [AUTOTITLE](/code-security/concepts/vulnerability-reporting-and-management/repository-security-advisories).
37-
* To ask for more information, or to open a discussion with the reporter, you can comment on the advisory. Any comments are visible only to the reporter and to any collaborators on the advisory.
39+
* To ask for more information, or to open a discussion with the reporter, you can comment on the advisory. A regular comment is visible to the reporter and all collaborators on the advisory.
3840
* If you have enough information to determine that the problem the reporter describes is not a security risk, click **Close security advisory**. Where possible, you should add a comment explaining why you don't consider the report a security risk before you close the advisory.
3941

4042
![Screenshot showing the options available to the repository maintainer when reviewing an externally submitted vulnerability report.](/assets/images/help/security/advisory-maintainer-options.png)
43+
44+
## Discussing a report with people who have write access
45+
46+
People with write access to the repository can use confidential comments to coordinate with each other. These comments are hidden from the reporter and invited advisory collaborators who do not have write access.
47+
48+
Access to confidential comments is based on current repository permissions. If a person's write access is removed, they can no longer read confidential comments. People who gain write access can read existing confidential comments.
49+
50+
1. In the advisory, type your comment.
51+
1. Below the comment field, select **Confidential. Only maintainers will see this comment**.
52+
1. Click **Comment**.
53+
54+
You can edit or delete a confidential comment if you still have write access to the repository. You cannot change a comment from regular to confidential, or from confidential to regular, after posting it.

‎content/code-security/how-tos/report-and-fix-vulnerabilities/report-privately.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ category:
2424

2525
> [!NOTE]
2626
> * If you have admin or security permissions for a public repository, you don’t need to submit a vulnerability report. Instead, create a draft security advisory directly. See [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/create-repository-advisory).
27-
> * Private vulnerability reporting is separate from a repository’s `SECURITY.md` file. You can only report vulnerabilities privately for repositories where this feature is enabled, and you don’t need to follow the instructions in `SECURITY.md`.
27+
> * Private vulnerability reporting is separate from a repository’s `SECURITY.md` file. You can only report vulnerabilities privately for repositories where this feature is enabled. If the repository has a security policy, the policy is displayed above the reporting form so you can review the maintainer's guidance before submitting.
2828
2929
If a public repository has private vulnerability reporting enabled, anyone can submit a private vulnerability report to the repository maintainers.
3030

‎content/code-security/reference/permissions/repository-security-advisory.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,8 @@ Add and remove credits for a security advisory (see [AUTOTITLE](/code-security/h
4040
Close the draft security advisory | {% octicon "x" aria-label="No" %} | {% octicon "check" aria-label="Yes" %} |
4141
Publish the security advisory (see [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/publish-repository-advisory)) | {% octicon "x" aria-label="No" %} | {% octicon "check" aria-label="Yes" %} |
4242

43+
Repository security advisory collaborators without write access to the repository cannot create or view confidential comments. This restriction includes the reporter of a privately reported vulnerability unless they also have write access. See [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/manage-vulnerability-reports#discussing-a-report-with-people-who-have-write-access).
44+
4345
### Permission differences for global security advisories
4446

4547
Unlike repository security advisories, anyone can contribute to **global security advisories** in the {% data variables.product.prodname_advisory_database %} at [github.com/advisories](https://github.com/advisories). Edits to global advisories will not change or affect how the advisory appears on the repository. See [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/edit-advisory-database).

‎content/communities/setting-up-your-project-for-healthy-contributions/creating-a-default-community-health-file.md‎

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,6 +72,9 @@ You can create defaults in your organization or personal account for the followi
7272
| {% endif %} |
7373
| Issue and pull request templates and _config.yml_ | Issue and pull request templates customize and standardize the information you'd like contributors to include when they open issues and pull requests in your repository. For more information, see [AUTOTITLE](/communities/using-templates-to-encourage-useful-issues-and-pull-requests/about-issue-and-pull-request-templates).<br /><br />If an issue template sets a label, that label must be created in your `.github` repository and any repositories where the template will be used. |
7474
| _SECURITY.md_ | A SECURITY file gives instructions on how to report a security vulnerability in your project and description that hyperlinks the file. For more information, see [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/add-security-policy). |
75+
| {% ifversion fpt or ghec %} |
76+
| _VULNERABILITY_REPORT.yml_ or _VULNERABILITY_REPORT.yaml_ | A vulnerability report form customizes the information that reporters must provide when they privately report a vulnerability. For more information, see [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/configure-vulnerability-reporting/configure-for-a-repository#customizing-the-vulnerability-reporting-form). |
77+
| {% endif %} |
7578
| _SUPPORT.md_ | A SUPPORT file lets people know about ways to get help with your project. For more information, see [AUTOTITLE](/communities/setting-up-your-project-for-healthy-contributions/adding-support-resources-to-your-project). |
7679

7780
You cannot create a default license file. License files must be added to individual repositories so the file will be included when a project is cloned, packaged, or downloaded.
@@ -86,4 +89,10 @@ You cannot create a default license file. License files must be added to individ
8689
1. {% ifversion ghec %}If you are creating the repository for an {% data variables.enterprise.prodname_emu_org %}, set the repository status to **Internal**. For any other eligible account, set the status to **Public**.{% else %}Make sure the repository status is set to **Public**.{% endif %} A repository for default files cannot be private.
8790
{% data reusables.repositories.initialize-with-readme %}
8891
{% data reusables.repositories.create-repo %}
89-
1. In the repository, create one of the supported community health files. Discussion category forms must be in a folder called `.github/DISCUSSION_TEMPLATE`. Issue templates and their configuration file must be in a folder called `.github/ISSUE_TEMPLATE`. {% ifversion fpt or ghec %}A `FUNDING.yml` file must be in the `.github` folder. {% endif %}All other supported files may be in the root of the repository, the `.github` folder, or the `docs` folder. For more information, see [AUTOTITLE](/repositories/working-with-files/managing-files/creating-new-files).
92+
1. In the repository, create one of the supported community health files. Store the file in the required location:
93+
* Store discussion category forms in `.github/DISCUSSION_TEMPLATE`.
94+
* Store issue templates and their configuration file in `.github/ISSUE_TEMPLATE`.
95+
{% ifversion fpt or ghec %}* Store `FUNDING.yml`, `VULNERABILITY_REPORT.yml`, and `VULNERABILITY_REPORT.yaml` in the `.github` folder.{% endif %}
96+
* Store all other supported files in the root of the repository, the `.github` folder, or the `docs` folder.
97+
98+
For more information, see [AUTOTITLE](/repositories/working-with-files/managing-files/creating-new-files).

‎content/communities/using-templates-to-encourage-useful-issues-and-pull-requests/syntax-for-githubs-form-schema.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -132,6 +132,7 @@ You can use a `textarea` element to add a multi-line text field to your form. Co
132132
| Key | Description | Required | Type | Default | Valid values |
133133
| --- | ----------- | -------- | ---- | ------- | ------- |
134134
{% data reusables.form-schema.required-key %}
135+
{% data reusables.form-schema.min-length-key %}
135136

136137
#### Example of `textarea`
137138

@@ -150,6 +151,7 @@ body:
150151
render: bash
151152
validations:
152153
required: true
154+
min_length: 100
153155
```
154156

155157
### `input`
@@ -174,6 +176,7 @@ You can use an `input` element to add a single-line text field to your form.
174176
| Key | Description | Required | Type | Default | Valid values |
175177
| --- | ----------- | -------- | ---- | ------- | ------- |
176178
{% data reusables.form-schema.required-key %}
179+
{% data reusables.form-schema.min-length-key %}
177180

178181
#### Example of `input`
179182

@@ -187,6 +190,7 @@ body:
187190
placeholder: "Example: Whenever I visit the personal account page (1-2 times a week)"
188191
validations:
189192
required: true
193+
min_length: 20
190194
```
191195

192196
### `dropdown`
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
| `min_length` | Prevents form submission until the response contains at least the specified number of characters. | {% octicon "x" aria-label="Optional" %} | Integer | {% octicon "dash" aria-label="Not applicable" %} | A non-negative integer |
Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,3 @@
1-
Security researchers can also use the REST API to privately report security vulnerabilities. See [AUTOTITLE](/rest/security-advisories/repository-advisories#privately-report-a-security-vulnerability).
1+
Security researchers can also use the REST API to privately report security vulnerabilities. API submissions use a Markdown `description`. If the repository or its owner's `.github` repository defines a custom vulnerability reporting form, the API description must contain the required sections and responses from that form. The built-in default form is not enforced for API submissions.
2+
3+
You can use the REST API to retrieve the custom form that applies to a repository. See [AUTOTITLE](/rest/security-advisories/repository-advisories).

‎data/reusables/security-advisory/reporting-a-vulnerability-non-admin.md‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{% data reusables.repositories.navigate-to-repo %}
22
{% data reusables.repositories.sidebar-security %}
33
1. Click **Report a vulnerability** to open the advisory form.
4-
1. Fill in the advisory details form.
4+
1. If the repository has a security policy, review the policy displayed above the form.
5+
1. Fill in the vulnerability reporting form.
56

67
> [!TIP]
7-
> In this form, only the title and description are mandatory. (In the general draft security advisory form, which the repository maintainer initiates, specifying the ecosystem is also required.) However, we recommend security researchers provide as much information as possible on the form so that the maintainers can make an informed decision about the submitted report. You can adopt the template used by our security researchers from the {% data variables.product.prodname_security %}, which is available on the [`github/securitylab` repository](https://github.com/github/securitylab/blob/main/docs/report-template.md).
8-
9-
For more information about the fields available and guidance on filling in the form, see [AUTOTITLE](/code-security/how-tos/report-and-fix-vulnerabilities/fix-reported-vulnerabilities/create-repository-advisory) and [AUTOTITLE](/code-security/tutorials/fix-reported-vulnerabilities/write-security-advisories).
8+
> By default, you must provide a summary, details, proof of concept, and impact statement. Maintainers can customize the form and require other information. Provide enough detail for the maintainers to reproduce and assess the vulnerability.
109
10+
1. Optionally, select **I used AI assistance to find or write up this report**.
1111
1. At the bottom of the form, click **Submit report**. {% data variables.product.prodname_dotcom %} will display a message letting you know that maintainers have been notified and that you have a pending credit for this security advisory.
1212

1313
> [!TIP]

0 commit comments

Comments
 (0)