GitHub adds maintainer-only comments to security advisories, and a REST API for the rest
GitHub made two changes to repository security advisories on 2 October, both about the discussion attached to a vulnerability report.
Confidential comments. Maintainers can now mark a comment on an advisory as confidential. Only people with write access to the repository can read it; the reporter and other invited collaborators without write access cannot see it and are not notified. Until now every comment was visible to everyone on the advisory, including the person who reported the bug, so teams that wanted to discuss suspected abuse, investigation details or coordination took the conversation elsewhere and lost it from the advisory's history.
The rules are strict. Access follows current repository permissions, so someone who loses write access also loses the confidential comments. Each view is recorded in the audit log. A comment cannot be switched between confidential and regular after posting, and confidential comments are marked in the timeline. They are available through the GraphQL API but not the REST API. The feature applies to public repositories that have private vulnerability reporting enabled, on all plans from Free to Enterprise Cloud.
A REST API for advisory comments. In a separate public preview, the REST API can now list, add and edit comments on repository security advisories, including those created from private vulnerability reports. Listing can be limited to comments updated since a given time. Advisory responses now carry a comment count, and global advisory responses include the count for the linked repository advisory, so a tool can see which advisories have discussion before fetching it. Those counts cover non-confidential comments only. Deletion is not yet supported. GitHub's suggested uses are exporting advisory discussions for audits and migrations, adding triage notes automatically, and building workflows like the ones teams already run for issues and pull requests.
The two changes meet at one boundary: the REST endpoints never return confidential comments, and non-collaborators cannot read internal ones. Access otherwise follows the advisory itself, with the repository security advisories permission or token scope.

What it means
Triage can now stay in the advisory without being read by the reporter, which matters most when the report itself is suspect. Teams that automate around advisories should note the split: an audit export through REST will be missing the confidential part of the record, and only GraphQL can retrieve it.