Rate limits for private vulnerability reports
Summary
Open source maintainers are receiving more low-quality and automated vulnerability reports, which can bury the reports that matter. Rate limits cap how many new reports a single account can submit… The post Rate limits for private vulnerability reports appeared first on The GitHub Blog .
Original Text
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd"> Open source maintainers are receiving more low-quality and automated vulnerability reports, which can bury the reports that matter. Rate limits cap how many new reports a single account can submit in a day, both to your repository and across GitHub. This helps protect you from bulk and automated submissions, while legitimate researchers can still reach you.
With this update:
Private vulnerability reporting now applies daily per-user rate limits to new reports.
Reporters who reach a limit see a message asking them to try again later.
Limits apply only to new reports. Comments on existing advisories aren’t affected.
Repository administrators can set a custom daily overall reporting limit for their repository.
Repository administrators can add trusted reporters to an allow list so they’re never rate limited.
To configure these settings, go to your repository’s settings, select Advanced Security, and click Settings next to “Private vulnerability reporting.”
This is available for public repositories with private vulnerability reporting enabled on GitHub Free, GitHub Pro, GitHub Team, and GitHub Enterprise Cloud.
Learn more in our docs about configuring private vulnerability reporting.
The post Rate limits for private vulnerability reports appeared first on The GitHub Blog.
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.