POST
/repos/{owner}/{repo}/security-advisories/reportsPrivately report a security vulnerability
Report a security vulnerability to the maintainers of the repository. See "Privately reporting a security vulnerability" for more information about private vulnerability reporting.
- RetriesRetries up to 2×, 500ms backoff, 30s timeout.
ownerstringrequired
The account owner of the repository. The name is not case sensitive.
repostringrequired
The name of the repository without the `.git` extension. The name is not case sensitive.
summarystringrequired
A short summary of the advisory.
descriptionstringrequired
A detailed description of what the advisory impacts.
vulnerabilitiesarray<object>optional
An array of products affected by the vulnerability detailed in a repository security advisory.
cwe_idsarray<string>optional
A list of Common Weakness Enumeration (CWE) IDs.
severitystringoptional
The severity of the advisory. You must choose between setting this field or `cvss_vector_string`.
cvss_vector_stringstringoptional
The CVSS vector that calculates the severity of the advisory. You must choose between setting this field or `severity`.
start_private_forkbooleanoptional
Whether to create a temporary private fork of the repository to collaborate on a fix.
201Response
ghsa_idstringrequired
The GitHub Security Advisory ID.
cve_idstringrequired
The Common Vulnerabilities and Exposures (CVE) ID.
urlstringrequired
The API URL for the advisory.
html_urlstringrequired
The URL for the advisory.
summarystringrequired
A short summary of the advisory.
descriptionstringrequired
A detailed description of what the advisory entails.
severitystringrequired
The severity of the advisory.
authorobjectrequired
The author of the advisory.
publisherobjectrequired
The publisher of the advisory.
identifiersarray<object>required
statestringrequired
The state of the advisory.
created_atstringrequired
The date and time of when the advisory was created, in ISO 8601 format.
updated_atstringrequired
The date and time of when the advisory was last updated, in ISO 8601 format.
published_atstringrequired
The date and time of when the advisory was published, in ISO 8601 format.
closed_atstringrequired
The date and time of when the advisory was closed, in ISO 8601 format.
withdrawn_atstringrequired
The date and time of when the advisory was withdrawn, in ISO 8601 format.
submissionobjectrequired
vulnerabilitiesarray<object>required
cvssobjectrequired
cvss_severitiesobjectoptional
cwesarray<object>required
cwe_idsarray<string>required
A list of only the CWE IDs.
creditsarray<object>required
credits_detailedarray<object>required
collaborating_usersarray<SimpleUser>required
A list of users that collaborate on the advisory.
collaborating_teamsarray<Team>required
A list of teams that collaborate on the advisory.
private_forkobjectrequired
A temporary private fork of the advisory's repository for collaborating on a fix.
403Forbidden
messagestringoptional
documentation_urlstringoptional
urlstringoptional
statusstringoptional
404Resource not found
messagestringoptional
documentation_urlstringoptional
urlstringoptional
statusstringoptional
422Validation failed.
2 documented failures
missing_sectiondescriptionunchecked_required_optiondescription
messagestringrequired
documentation_urlstringrequired
errorsarray<object>optional
Error handling
A 403 is returned: Forbidden. A 404 is returned: Resource not found. A 422 is returned: Validation failed.
Was this helpful?