GHAS customers can publish private security advisories and Dependabot updates [GA]
- Dominant language
- No language data
- Stars
- 8.9k
- Forks
- 1.8k
- PR merge metrics
- No merged PRs in 30d
Description
### Value Prop
With this update, enterprises using GitHub Advanced Security can now publish private security advisories and trigger Dependabot updates that are scoped only to their internal repositories. This empowers organizations to manage vulnerabilities for internal or pre-release packages, ensuring that both producers and consumers within the enterprise stay protected without exposing sensitive information publicly.
### Expected Outcome
By enabling private advisories and internal Dependabot updates, organizations can respond faster to security issues in their own software supply chain. This helps teams keep their code secure and up to date, while maintaining control over when and how vulnerabilities are disclosed.
Contributor guide
Assessment
This issue has not been assessed yet.