Repository security advisory comments API in public preview

You can now read, add, and edit comments on repository security advisories using the REST API, including advisories created from private vulnerability reports.

Until now, the discussion on an advisory was only reachable in the web UI, even though it often holds the most useful triage context on a vulnerability report. With the new endpoints, you can:

  • List the comments on a repository security advisory, optionally limited to those updated since a given time.
  • Get a single comment.
  • Add a comment.
  • Edit a comment.

Repository security advisory responses also now include a comments count, and global advisory responses include the count for their linked repository advisory, so you can tell which advisories have discussion before you fetch it. These fields count non-confidential comments and help identify advisories with comment activity before fetching the comments.

This helps you export advisory discussions for audits and migrations, automatically add triage notes, and build advisory workflows that work the same way as the ones you already have for issues and pull requests.

A few things to know:

  • Access follows the same rules as the advisory itself. You need the repository security advisories scope, and anyone who can’t see an advisory can’t see its comments.
  • Access requires permission to view the advisory and the appropriate read or write repository security advisories permission or token scope. Non-collaborators cannot view internal comments, and confidential comments are not returned by these REST endpoints.
  • Deleting comments isn’t supported yet through the API.

This is available in public preview for public repositories on GitHub Free, GitHub Pro, GitHub Team, and GitHub Enterprise Cloud.

Learn more in our REST API docs.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论