GitHub made structured forms the default for private vulnerability reports, requiring reporters to fill in summary, details, a proof of concept of at least 150 characters, and impact, after saying a single free-text box made low-quality and AI-generated reports easy to submit and hard to triage. Maintainers can customize the form with a .github/VULNERABILITY_REPORT.yml file in a repository or a shared .github repository, use issue-form syntax and minimum-length fields, require a CWE before submission, and point reporters to a SECURITY.md banner, while reporters get an option to disclose AI assistance. Custom forms are enforced for REST API submissions so existing integrations keep working, and the change came alongside GitHub’s daily rate limits on new private vulnerability reports.
GitHub requires structured forms for private vulnerability reports to cut AI-generated noise
GitHub made structured forms the default for private vulnerability reports, requiring reporters to fill in summary, details, a proof of concept of at least 150 characters, and impact, after saying a single free-text box made low-quality and AI-generated reports easy to submit and hard to triage. Maintainers can customize the form with a .github/VULNERABILITY_REPORT.yml file in a repository or a shared .github repository, use issue-form syntax and minimum-length fields, require a CWE before submission, and point reporters to a SECURITY.md banner, while reporters get an option to disclose AI assistance. Custom forms are enforced for REST API submissions so existing integrations keep working, and the change came alongside GitHub's daily rate limits on new private vulnerability reports.
Source: GitHub Blog