Skip to content

Commit 067e875

Browse files
authored
Merge pull request github#32984 from github/repo-sync
Repo sync
2 parents 208859d + a4a55a8 commit 067e875

13 files changed

+20
-48
lines changed

content/code-security/getting-started/github-security-features.md

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -25,14 +25,6 @@ The {% data variables.product.prodname_advisory_database %} contains a curated l
2525

2626
Make it easy for your users to confidentially report security vulnerabilities they've found in your repository. For more information, see "[AUTOTITLE](/code-security/getting-started/adding-a-security-policy-to-your-repository)."
2727

28-
{% ifversion fpt or ghec %}
29-
30-
### Security advisories
31-
32-
Privately discuss and fix security vulnerabilities in your repository's code. You can then publish a security advisory to alert your community to the vulnerability and encourage community members to upgrade. For more information, see "[AUTOTITLE](/code-security/security-advisories/working-with-repository-security-advisories/about-repository-security-advisories)."
33-
34-
{% endif %}
35-
3628
### {% data variables.product.prodname_dependabot_alerts %} and security updates
3729

3830
View alerts about dependencies that are known to contain security vulnerabilities, and choose whether to have pull requests generated automatically to update these dependencies. For more information, see "[AUTOTITLE](/code-security/dependabot/dependabot-alerts/about-dependabot-alerts)"
@@ -75,6 +67,14 @@ Security overview shows which security features are enabled for the repository,
7567

7668
## Available for free public repositories
7769

70+
{% ifversion fpt or ghec %}
71+
72+
### Security advisories
73+
74+
Privately discuss and fix security vulnerabilities in your repository's code. You can then publish a security advisory to alert your community to the vulnerability and encourage community members to upgrade. For more information, see "[AUTOTITLE](/code-security/security-advisories/working-with-repository-security-advisories/about-repository-security-advisories)."
75+
76+
{% endif %}
77+
7878
### {% data variables.secret-scanning.user_alerts_caps %}
7979

8080
Automatically detect tokens or credentials that have been checked into a {% ifversion ghec %}user-owned {% endif %}public repository. You can view alerts for any secrets that {% data variables.product.company_short %} finds in your code, in the **Security** tab of the repository, so that you know which tokens or credentials to treat as compromised. For more information, see "[AUTOTITLE](/code-security/secret-scanning/about-secret-scanning#about-secret-scanning-alerts-for-users)."

content/code-security/getting-started/quickstart-for-securing-your-repository.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -157,7 +157,7 @@ You can view and manage alerts from security features to address dependencies an
157157

158158
You can also use {% data variables.product.prodname_dotcom %}'s tools to audit responses to security alerts. For more information, see "[AUTOTITLE](/code-security/getting-started/auditing-security-alerts)".
159159

160-
{% ifversion fpt or ghec %}If you have a security vulnerability, you can create a security advisory to privately discuss and fix the vulnerability. For more information, see "[AUTOTITLE](/code-security/security-advisories/working-with-repository-security-advisories/about-repository-security-advisories)" and "[AUTOTITLE](/code-security/security-advisories/working-with-repository-security-advisories/creating-a-repository-security-advisory)."
160+
{% ifversion fpt or ghec %}If you have a security vulnerability in a public repository, you can create a security advisory to privately discuss and fix the vulnerability. For more information, see "[AUTOTITLE](/code-security/security-advisories/working-with-repository-security-advisories/about-repository-security-advisories)" and "[AUTOTITLE](/code-security/security-advisories/working-with-repository-security-advisories/creating-a-repository-security-advisory)."
161161
{% endif %}
162162

163163
{% data reusables.security-overview.security-information-about-actions %}

content/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/best-practices-for-writing-repository-security-advisories.md

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -14,9 +14,7 @@ redirect_from:
1414
- /code-security/security-advisories/guidance-on-reporting-and-writing/best-practices-for-writing-repository-security-advisories
1515
---
1616

17-
{% data reusables.security-advisory.private-repository-non-ghas-deprecation-note %}
18-
19-
Anyone with admin permissions to a repository can create and edit a security advisory.
17+
Anyone with admin permissions to a public repository can create and edit a security advisory.
2018

2119
{% data reusables.security-advisory.security-researcher-cannot-create-advisory %}
2220

@@ -72,8 +70,8 @@ We recommend that you use the **Affected versions** field to specify which versi
7270
{% note %}
7371

7472
**Notes:** The lower-bound limitation:
75-
- is due to incompatibilities with the OSV (Open Source Vulnerability) schema.
76-
- only applies when you make a suggestion on an existing advisory in the {% data variables.product.prodname_advisory_database %}.
73+
- Is due to incompatibilities with the OSV (Open Source Vulnerability) schema.
74+
- Only applies when you make a suggestion on an existing advisory in the {% data variables.product.prodname_advisory_database %}.
7775

7876
{% endnote %}
7977

content/code-security/security-advisories/working-with-repository-security-advisories/about-repository-security-advisories.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: About repository security advisories
3-
intro: 'You can use repository security advisories to privately discuss, fix, and publish information about security vulnerabilities in your repository.'
3+
intro: 'You can use repository security advisories to privately discuss, fix, and publish information about security vulnerabilities in your public repository.'
44
shortTitle: About repository security advisories
55
redirect_from:
66
- /articles/about-maintainer-security-advisories
@@ -19,8 +19,6 @@ topics:
1919
- CVEs
2020
---
2121

22-
{% data reusables.security-advisory.private-repository-non-ghas-deprecation-note %}
23-
2422
{% data reusables.repositories.security-advisory-admin-permissions %}
2523

2624
{% data reusables.security-advisory.security-researcher-cannot-create-advisory %}

content/code-security/security-advisories/working-with-repository-security-advisories/collaborating-in-a-temporary-private-fork-to-resolve-a-repository-security-vulnerability.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: Collaborating in a temporary private fork to resolve a repository security vulnerability
3-
intro: You can create a temporary private fork to privately collaborate on fixing a security vulnerability in your repository.
3+
intro: You can create a temporary private fork to privately collaborate on fixing a security vulnerability in your public repository.
44
redirect_from:
55
- /articles/collaborating-in-a-temporary-private-fork-to-resolve-a-security-vulnerability
66
- /github/managing-security-vulnerabilities/collaborating-in-a-temporary-private-fork-to-resolve-a-security-vulnerability

content/code-security/security-advisories/working-with-repository-security-advisories/creating-a-repository-security-advisory.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Creating a repository security advisory
33
intro: You can create a draft security advisory to privately discuss and fix a security vulnerability in your open source project.
4-
permissions: Anyone with admin permissions to a repository, or with a security manager role within the repository, can create a security advisory.
4+
permissions: Anyone with admin permissions to a public repository, or with a security manager role within the repository, can create a security advisory.
55
redirect_from:
66
- /articles/creating-a-maintainer-security-advisory
77
- /github/managing-security-vulnerabilities/creating-a-maintainer-security-advisory
@@ -19,8 +19,6 @@ topics:
1919
shortTitle: Create repository advisories
2020
---
2121

22-
{% data reusables.security-advisory.private-repository-non-ghas-deprecation-note %}
23-
2422
{% data reusables.security-advisory.security-researcher-cannot-create-advisory %}
2523

2624
## Creating a security advisory

content/code-security/security-advisories/working-with-repository-security-advisories/index.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Working with repository security advisories
33
shortTitle: Repository security advisories
4-
intro: 'Discuss, fix, and disclose security vulnerabilities in your repositories using repository security advisories.'
4+
intro: 'Discuss, fix, and disclose security vulnerabilities in your public repositories using repository security advisories.'
55
redirect_from:
66
- /articles/managing-security-vulnerabilities-in-your-project
77
- /github/managing-security-vulnerabilities/managing-security-vulnerabilities-in-your-project
@@ -29,5 +29,3 @@ children:
2929
- /removing-a-collaborator-from-a-repository-security-advisory
3030
- /deleting-a-repository-security-advisory
3131
---
32-
33-
{% data reusables.security-advisory.private-repository-non-ghas-deprecation-note %}

content/rest/security-advisories/repository-advisories.md

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,4 @@ topics:
1111
autogenerated: rest
1212
---
1313

14-
{% data reusables.security-advisory.private-repository-non-ghas-deprecation-note-api %}
15-
1614
<!-- Content after this section is automatically generated -->
Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,3 @@
1-
Anyone with admin permissions to a repository can create a security advisory.
1+
Anyone with admin permissions to a public repository can create a security advisory.
22

3-
Anyone with admin permissions to a repository also has admin permissions to all security advisories in that repository. People with admin permissions to a security advisory can add collaborators, and collaborators have write permissions to the security advisory.
3+
Anyone with admin permissions to a public repository also has admin permissions to all security advisories in that repository. People with admin permissions to a security advisory can add collaborators, and collaborators have write permissions to the security advisory.

data/reusables/security-advisory/private-repository-non-ghas-deprecation-note-api.md

Lines changed: 0 additions & 9 deletions
This file was deleted.

0 commit comments

Comments
 (0)