A More Visible Way to Say Thanks

Since Security Advisories launched, GitHub has been collecting maintainer feedback on how the feature is used. A recurring request was a straightforward way to acknowledge the people who helped with an advisory. Many maintainers were already doing this informally—about 20% of advisory descriptions mention someone by name, often crediting everything from vulnerability discovery and patch creation to moral support.

Advisory Credits

To make that recognition more prominent, GitHub has introduced advisory credits as a core part of the Security Advisory workflow. Anyone viewing an advisory can now see who contributed, both in the repository and in the GitHub Advisory Database.

Adding a credit is straightforward: while editing a Security Advisory, use the Credits area at the bottom to search for the GitHub user you want to acknowledge, then press Enter.

Credited users have the option to accept or decline the credit. When accepted, the credit appears on the advisory in both locations. GitHub has also processed mentions from previously published advisories into pending credits, so maintainers who already acknowledged contributors in text don't need to re-add them.

Recognizing Collaboration

Advisory credits are meant to shine a light on the collaborative work that keeps open source secure. By formalizing the thank-you, GitHub aims to celebrate the contributions that make these efforts possible.