GitHub introduced daily per-account rate limits for new private vulnerability reports, saying open source maintainers are receiving more low-quality and automated reports that bury the ones that matter. Repository administrators can set a custom daily limit for their repository and add trusted reporters to an allow list so they are never throttled, the limits apply only to new reports and not to comments on existing advisories, and the controls are available for public repositories with private vulnerability reporting enabled on GitHub Free, Pro, Team and Enterprise Cloud.
GitHub adds daily rate limits for private vulnerability reports
GitHub introduced daily per-account rate limits for new private vulnerability reports, saying open source maintainers are receiving more low-quality and automated reports that bury the ones that matter. Repository administrators can set a custom daily limit for their repository and add trusted reporters to an allow list so they are never throttled, the limits apply only to new reports and not to comments on existing advisories, and the controls are available for public repositories with private vulnerability reporting enabled on GitHub Free, Pro, Team and Enterprise Cloud.
Source: GitHub Blog