{
  "id": 12207679,
  "title": "GitHub Slams the Brakes on Private Vulnerability Reports",
  "url": "https://urgent.news/2026/10/05/github-slams-the-brakes-on-private-vulnerability-reports",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-05T17:51:35.000Z",
  "source": {
    "name": "DevOps.com",
    "slug": "devops-com",
    "url": "https://devops.com/github-slams-the-brakes-on-private-vulnerability-reports/"
  },
  "original_language": "en",
  "account": "GitHub has implemented new limits on private vulnerability reports to address the overwhelming influx of automated and low-quality submissions. This move reflects the company's acknowledgment that human maintainers struggle to handle the massive volume of reports while still managing legitimate, high-quality disclosures. The new daily rate limits on private vulnerability reports aim to give maintainers time to focus on the most relevant and high-quality reports without completely shutting off the private disclosure channels for genuine researchers. These restrictions don't apply to existing reports and allow repository administrators to create custom limits and exempt trusted contributors from the caps. GitHub also introduced structured forms for private vulnerability reports, which require maintainers to request additional information such as reproducible proof of concept, aiming to improve the signal-to-noise ratio at the intake stage.",
  "summary": "Drowning in AI-generated bug reports? GitHub has a radical answer: Stop accounts from reporting them. GitHub’s new limits on bug reports aren’t a solution to the AI bug-report flood. Anything but! They’re an admission that the traditional security-disclosure workflow, with human maintainers in the loop, simply doesn’t scale. The scarce resource is no longer discovering […]",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}