GitHub has introduced a new REST API for repository security advisories, allowing developers and security teams to programmatically read, add, and edit comments on advisories—including those generated from private vulnerability reports. The feature is now available in public preview, expanding the ways organizations can interact with security discussions in their repositories. The announcement was published on the GitHub Blog.
This update addresses a gap in GitHub’s security tooling by enabling automation around advisory discussions. Previously, users had to manually manage comments on advisories through the web interface. Now, teams can integrate comment workflows into their existing tools, such as issue trackers or internal dashboards, using standard REST API calls. For organizations that rely on private vulnerability reports, this means they can now programmatically engage with discussions tied to those reports, which were previously limited to manual interaction.
The API supports standard REST operations: retrieving existing comments, posting new ones, and updating or deleting them as needed. This aligns with GitHub’s broader push to make security workflows more extensible for developers who prefer automation. For example, a team could write a script to automatically post a comment on an advisory when a related pull request is merged, or use the API to surface advisory discussions in a custom security dashboard. The ability to edit comments also opens possibilities for collaborative triage processes, where multiple stakeholders can refine their feedback without duplicating effort.
There are no additional costs associated with accessing this feature during its public preview period. GitHub has not indicated any pricing changes for the API, and it is available to all users with appropriate repository permissions. This is a GitHub-native feature and is not part of Mina Labs’ offerings. Mina Labs does not provide, sell, or manage this API or any related GitHub tools.
Developers might use this API to streamline security triage processes. For instance, a security engineer could build a bot that automatically responds to new advisories with templated guidance for developers, reducing the time spent on initial discussions. Alternatively, teams could integrate advisory comments into their existing issue management systems, ensuring that security-related conversations are visible alongside code changes. This could be particularly useful for organizations with distributed teams, where centralized visibility into security discussions helps maintain alignment.
Another potential use case involves auditing and compliance workflows. By pulling comments via the API, organizations can generate reports on advisory discussions over time, tracking how vulnerabilities are addressed and documented. This could support internal audits or external compliance checks, where evidence of security discussions is required. The ability to programmatically archive or export these comments simplifies record-keeping compared to manually copying information from the web interface.
The public preview also provides an opportunity for early adopters to test the API’s capabilities and provide feedback to GitHub. Teams interested in experimenting with it can begin integrating it into their workflows immediately, though they should be aware that changes may occur before the feature exits preview. GitHub has not yet announced a general availability date for this API.
For developers focused on security automation, this release removes a friction point in managing advisory discussions. It complements other GitHub security tools, such as Dependabot alerts and code scanning, by giving teams more control over the human conversations that often accompany technical fixes. As security practices evolve, APIs like this one help ensure that tooling can adapt alongside them.
MINA LABS
Start creating free