Skip to content

Commit fa7cc51

Browse files
authored
Merge pull request #36988 from github/repo-sync
Repo sync
2 parents 331ed35 + 1218d90 commit fa7cc51

27 files changed

Lines changed: 268 additions & 40 deletions

File tree

content/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/best-practices-for-writing-repository-security-advisories.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@ intro: 'When you create or edit security advisories, the information you provide
44
versions:
55
fpt: '*'
66
ghec: '*'
7+
permissions: '{% data reusables.permissions.security-repo-enable %}'
78
type: how_to
89
topics:
910
- Security advisories
@@ -14,8 +15,6 @@ redirect_from:
1415
- /code-security/security-advisories/guidance-on-reporting-and-writing/best-practices-for-writing-repository-security-advisories
1516
---
1617

17-
Anyone with admin permissions to a public repository can create and edit a security advisory.
18-
1918
{% data reusables.security-advisory.security-researcher-cannot-create-advisory %}
2019

2120
## About security advisories for repositories

content/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/managing-privately-reported-security-vulnerabilities.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Managing privately reported security vulnerabilities
33
intro: Repository maintainers can manage security vulnerabilities that have been privately reported to them by security researchers for repositories where private vulnerability reporting is enabled.
4-
permissions: 'Anyone with admin permissions to a repository can see, review, and manage privately-reported vulnerabilities for the repository.'
4+
permissions: '{% data reusables.permissions.security-repo-enable %}'
55
versions:
66
fpt: '*'
77
ghec: '*'

content/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,7 @@ type: how_to
88
topics:
99
- Security advisories
1010
- Vulnerabilities
11+
permissions: '**Anyone** can privately report a security vulnerability to repository maintainers.'
1112
shortTitle: Privately reporting
1213
redirect_from:
1314
- /code-security/security-advisories/guidance-on-reporting-and-writing/privately-reporting-a-security-vulnerability

content/code-security/security-advisories/working-with-global-security-advisories-from-the-github-advisory-database/browsing-security-advisories-in-the-github-advisory-database.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
title: Browsing security advisories in the GitHub Advisory Database
33
intro: 'You can browse the {% data variables.product.prodname_advisory_database %} to find CVEs and {% data variables.product.prodname_dotcom %}-originated advisories affecting the open source world.'
44
shortTitle: Browse Advisory Database
5+
permissions: '{% data reusables.permissions.global-security-advisories-browse %}'
56
redirect_from:
67
- /github/managing-security-vulnerabilities/browsing-security-vulnerabilities-in-the-github-advisory-database
78
- /code-security/supply-chain-security/browsing-security-vulnerabilities-in-the-github-advisory-database

content/code-security/security-advisories/working-with-global-security-advisories-from-the-github-advisory-database/editing-security-advisories-in-the-github-advisory-database.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
---
22
title: Editing security advisories in the GitHub Advisory Database
33
intro: 'You can submit improvements to any advisory published in the {% data variables.product.prodname_advisory_database %} by making a community contribution.'
4+
permissions: '{% data reusables.permissions.global-security-advisories-edit %}'
45
redirect_from:
56
- /code-security/security-advisories/editing-security-advisories-in-the-github-advisory-database
67
- /code-security/supply-chain-security/managing-vulnerabilities-in-your-projects-dependencies/editing-security-advisories-in-the-github-advisory-database

content/code-security/security-advisories/working-with-repository-security-advisories/about-repository-security-advisories.md

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,16 +13,13 @@ versions:
1313
fpt: '*'
1414
ghec: '*'
1515
type: overview
16+
product: '{% data reusables.gated-features.private-vulnerability-reporting %}'
1617
topics:
1718
- Security advisories
1819
- Vulnerabilities
1920
- CVEs
2021
---
2122

22-
{% data reusables.repositories.security-advisory-admin-permissions %}
23-
24-
{% data reusables.security-advisory.security-researcher-cannot-create-advisory %}
25-
2623
## About repository security advisories
2724

2825
{% data reusables.security-advisory.disclosing-vulnerabilities %} For more information, see [AUTOTITLE](/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/about-coordinated-disclosure-of-security-vulnerabilities).

content/code-security/security-advisories/working-with-repository-security-advisories/adding-a-collaborator-to-a-repository-security-advisory.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
---
22
title: Adding a collaborator to a repository security advisory
33
intro: You can add other users or teams to collaborate on a security advisory with you.
4+
permissions: '{% data reusables.permissions.security-repo-enable %}'
45
redirect_from:
56
- /articles/adding-a-collaborator-to-a-maintainer-security-advisory
67
- /github/managing-security-vulnerabilities/adding-a-collaborator-to-a-maintainer-security-advisory
@@ -19,8 +20,6 @@ topics:
1920
shortTitle: Add collaborators
2021
---
2122

22-
People with admin permissions to a security advisory can add collaborators to the security advisory.
23-
2423
{% data reusables.security-advisory.repository-level-advisory-note %}
2524

2625
## Adding a collaborator to a security advisory

content/code-security/security-advisories/working-with-repository-security-advisories/collaborating-in-a-temporary-private-fork-to-resolve-a-repository-security-vulnerability.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
---
22
title: Collaborating in a temporary private fork to resolve a repository security vulnerability
33
intro: You can create a temporary private fork to privately collaborate on fixing a security vulnerability in your public repository.
4+
permissions: '{% data reusables.permissions.security-repo-enable %}'
45
redirect_from:
56
- /articles/collaborating-in-a-temporary-private-fork-to-resolve-a-security-vulnerability
67
- /github/managing-security-vulnerabilities/collaborating-in-a-temporary-private-fork-to-resolve-a-security-vulnerability
@@ -27,8 +28,6 @@ Before you can collaborate in a temporary private fork, you must create a draft
2728

2829
## Creating a temporary private fork
2930

30-
Anyone with admin permissions to a security advisory can create a temporary private fork.
31-
3231
To keep information about vulnerabilities secure, integrations, including CI, cannot access temporary private forks.
3332

3433
{% data reusables.repositories.navigate-to-repo %}

content/code-security/security-advisories/working-with-repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Configuring private vulnerability reporting for a repository
33
intro: Owners and administrators of public repositories can allow security researchers to report vulnerabilities securely in the repository by enabling private vulnerability reporting.
4-
permissions: Anyone with admin permissions to a public repository can enable and disable private vulnerability reporting for the repository.
4+
permissions: '{% data reusables.permissions.security-repo-enable %}'
55
versions:
66
fpt: '*'
77
ghec: '*'

content/code-security/security-advisories/working-with-repository-security-advisories/configuring-private-vulnerability-reporting-for-an-organization.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Configuring private vulnerability reporting for an organization
33
intro: Organization owners and security managers can allow security researchers to report vulnerabilities securely in repositories within the organization by enabling private vulnerability reporting for all its public repositories.
4-
permissions: 'Anyone with admin permissions to an organization, or with a security manager role within the organization, can enable and disable private vulnerability reporting for that organization.'
4+
permissions: '{% data reusables.permissions.security-org-enable %}'
55
versions:
66
fpt: '*'
77
ghec: '*'

0 commit comments

Comments
 (0)