Structured forms for private vulnerability reports
GitHub mandates structured forms for private vulnerability reports, requiring fields for summary, details, proof of concept, and impact. Developers can customize these forms via YAML configuration and enforce CWE assignment. This change aims to filter low-quality and AI-generated submissions while preserving API compatibility for existing integrations across supported GitHub plans.

GitHub introduces structured forms for private vulnerability reports to replace a single free-text box, which previously facilitated low-quality or AI-generated submissions. By default, reporters must complete four required fields: summary, details, impact, and a proof of concept containing at least 150 characters. These responses consolidate into the standard advisory description, allowing maintainers to review and edit them as usual. Repository owners can customize these forms using a .github/VULNERABILITY_REPORT.yml file or apply them across an organization via the .github repository. The configuration utilizes issue form syntax with min_length constraints; if the custom form is invalid, the system reverts to the default. Administrators can mandate CWE assignment through settings or enterprise policies, displaying a link to SECURITY.md if a security policy exists. Reporters may also disclose AI assistance. To ensure compatibility, the default form is not enforced on the REST API, allowing existing integrations to persist, though custom forms must be matched by API submissions, with errors directing users to a new endpoint for the required schema. This feature is available on GitHub Free, Pro, Team, and Enterprise Cloud.