
GitHub’s private vulnerability reporting feature, which has been tested since late last year, has now become generally available.
Going forward, maintainers of open-source projects will be able to communicate with security researchers directly, being tipped off on security issues without the risk of vulnerabilities making it to the public.