6 security settings every GitHub maintainer should enable this week

Imported from official source

Security notice

Cybersecurity Classified by Officially

At GitHub Security Lab, we spend a lot of our week talking to maintainers. Some find the settings page dense and the docs sprawl. Most maintainers we talk to weren’t hired to be security engineers. While this is true, ignoring a project’s security settings completely will lead into leaving a lot in the table in terms of automation and scalability, leading into a poor security posture, and before you realize it to vulnerabilities that pile up, exposing your users.

Here’s the short version. Six settings, free to use, updated in less than half an hour. We’ve bundled them into a guided flow called Protect Your Project so you can do them in one pass, and we walk through each tool you’ll use below.

1. Add a SECURITY.md file

This is the lightest-lift setting on the list and the one that makes everything else easier.

A SECURITY.md file tells the people who find bugs in your project where to send them. Without one, your options for a well-meaning reporter are a public issue (now a public exploit) or your personal email (if they can find it).

You don’t need to write much. We suggest adding a communication means such as an email so that those reporting vulnerabilities can reach you directly without posting about them publicly. Then, you can state what bugs are in scope, alongside anything else a reporter should have in mind when contacting you. For reference, we point maintainers to the the systemd project’s security policy that we consider a complete example. It sets clear expectations about reproducers and doesn’t assume you have a 24/7 response team when you don’t. Borrow the structure, change the contact details, commit it.

Ten minutes, tops.

2. Turn on private vulnerability reporting

SECURITY.md tells reporters where to go. Private vulnerability reporting (PVR) gives them a private place to make their report.

This is an extract. The publication continues at the source.

Read the original at the source: https://github.blog/security/6-security-settings-every-github-maintainer-should-enable-this-week/

Officially imported this from GitHub’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
GitHub — imported from official source
Official source
https://github.blog/security/feed/ RSS
Imported
September 15, 2026 20:57
Versions
1 recorded
Identity
https://github.blog/?p=97204

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.