Skip to main content

Repository security advisories

The actions you can take in a repository security advisory depend on whether you have admin or write permissions to the security advisory.

在本文中

Permissions overview

具有管理员角色的仓库所有者、组织所有者、安全管理员和用户可以:****

  • 为仓库创建安全公告。
  • 访问仓库的所有安全公告。
  • 添加协作者到安全通告。

协作者对安全通告具有写入权限。****

ActionWrite permissionsAdmin permissions
See a draft security advisory
Add collaborators to the security advisory (see Adding a collaborator to a repository security advisory)
Edit and delete any comments in the security advisory
Create a temporary private fork in the security advisory (see 在临时专用分支中协作以解决存储库安全漏洞)
Add changes to a temporary private fork in the security advisory (see 在临时专用分支中协作以解决存储库安全漏洞)
Create pull requests in a temporary private fork (see 在临时专用分支中协作以解决存储库安全漏洞)
Merge changes in the security advisory (see 在临时专用分支中协作以解决存储库安全漏洞)
Add and edit metadata in the security advisory (see Publishing a repository security advisory)
Add and remove credits for a security advisory (see Editing a repository security advisory)
Close the draft security advisory
Publish the security advisory (see Publishing a repository security advisory)

Permission differences for global security advisories

Unlike repository security advisories, anyone can contribute to global security advisories in the GitHub Advisory Database at github.com/advisories. Edits to global advisories will not change or affect how the advisory appears on the repository. See Editing security advisories in the GitHub Advisory Database.

Further reading