{"slug": "structured-forms-for-private-vulnerability-reports", "title": "Structured forms for private vulnerability reports", "summary": "GitHub now requires reporters filing private vulnerability reports to complete a structured form with four required fields — summary, details, a proof of concept of at least 150 characters, and impact — replacing the single free-text box that made low-quality or AI-generated reports easy to submit. Maintainers can customize the form via a .github/VULNERABILITY_REPORT.yml file on the default branch, require a CWE assignment through Settings > Advanced Security > Private vulnerability reporting, and reporters can check \"I used AI assistance to find or write up this report\" to disclose AI use. The feature is available for public repositories with private vulnerability reporting enabled on GitHub Free, GitHub Pro, GitHub Team, and GitHub Enterprise Cloud, and custom forms must be matched by REST API submissions, with mismatches returning an error pointing to a new endpoint that returns the enforced form.", "body_md": "# Structured forms for private vulnerability reports\n\nPrivate vulnerability reports can now use a structured form that asks reporters for the details you need to assess a vulnerability, including a reproducible proof of concept.\n\nA single free-text box made it easy to submit low-quality or AI-generated reports and hard for you to find the signal in them. Now, by default, reporters must fill in four required fields: summary, details, proof of concept (at least 150 characters), and impact. Their answers are combined into the advisory description, so you review and edit the report as you do today.\n\nWith this update:\n\n- You can customize the form by adding a `.github/VULNERABILITY_REPORT.yml` file to your repository’s default branch. To apply a form to all repositories you own, add it to your organization or account’s`.github` repository. Forms use issue form syntax, and fields support`min_length` so you can require a minimum level of detail. If your form is invalid, the default form is used.\n- You can require reporters to assign a CWE before they submit, from **Settings** >**Advanced Security** >**Private vulnerability reporting** . Organization and enterprise owners can enforce this setting through a policy.\n- If your repository has a security policy, reporters see a banner linking to your `SECURITY.md` before they submit.\n- Reporters can check “I used AI assistance to find or write up this report” to disclose AI use.\n\nIf you add a custom form, reports submitted through the REST API must match it. The default form isn’t enforced for the API, so existing integrations keep working. When an API submission doesn’t match, the error points to a new endpoint that returns the form your repository enforces.\n\nThis is available for public repositories with private vulnerability reporting enabled on GitHub Free, GitHub Pro, GitHub Team, and GitHub Enterprise Cloud.\n\n[Learn more about privately reporting a security vulnerability](https://docs.github.com/code-security/how-tos/report-and-fix-vulnerabilities/report-privately).", "url": "https://wpnews.pro/news/structured-forms-for-private-vulnerability-reports", "canonical_source": "https://github.blog/changelog/2026-10-01-structured-forms-for-private-vulnerability-reports", "published_at": "2026-10-01 19:57:28+00:00", "updated_at": "2026-10-01 21:51:21.605604+00:00", "lang": "en", "topics": ["ai-crawlers", "developer-tools"], "entities": ["GitHub", "GitHub Free", "GitHub Pro", "GitHub Team", "GitHub Enterprise Cloud", "CWE"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/structured-forms-for-private-vulnerability-reports", "markdown": "https://wpnews.pro/news/structured-forms-for-private-vulnerability-reports.md", "text": "https://wpnews.pro/news/structured-forms-for-private-vulnerability-reports.txt", "jsonld": "https://wpnews.pro/news/structured-forms-for-private-vulnerability-reports.jsonld"}}