Published October 1, 2026 · Added October 4, 2026

GitHub requires structured forms for private vulnerability reports to cut AI-generated noise

GitHub made structured forms the default for private vulnerability reports, requiring reporters to fill in summary, details, a proof of concept of at least 150 characters, and impact, after saying a single free-text box made low-quality and AI-generated reports easy to submit and hard to triage. Maintainers can customize the form with a .github/VULNERABILITY_REPORT.yml file in a repository or a shared .github repository, use issue-form syntax and minimum-length fields, require a CWE before submission, and point reporters to a SECURITY.md banner, while reporters get an option to disclose AI assistance. Custom forms are enforced for REST API submissions so existing integrations keep working, and the change came alongside GitHub's daily rate limits on new private vulnerability reports.

GitHub made structured forms the default for private vulnerability reports, requiring reporters to fill in summary, details, a proof of concept of at least 150 characters, and impact, after saying a single free-text box made low-quality and AI-generated reports easy to submit and hard to triage. Maintainers can customize the form with a .github/VULNERABILITY_REPORT.yml file in a repository or a shared .github repository, use issue-form syntax and minimum-length fields, require a CWE before submission, and point reporters to a SECURITY.md banner, while reporters get an option to disclose AI assistance. Custom forms are enforced for REST API submissions so existing integrations keep working, and the change came alongside GitHub’s daily rate limits on new private vulnerability reports.

Read the original story.

Source: GitHub Blog