Kit and GitHub: Vulnerability reports beyond the repo
GitHub private reporting keeps reports, patches and CVE requests with public repositories. Kit handles reports about the rest of your company, with response deadlines and bounty paperwork. You can use both.
Which fits your team?
Kit fits teams that need:
- A company-wide report and response record
- Intake for hosted products and private assets
- Reports without GitHub accounts or names
- Acknowledgment deadlines and breach records
- Tax forms and a bounty ledger, with payments sent manually
GitHub fits teams that need:
- Private reporting for public repositories
- Free CVE requests
- Private patch collaboration with reporters
- Advisories that notify supported dependencies
- REST access to the advisory queue
- A free reporting channel beside the code
What GitHub does well
CVE requests, private patches and a report button on the repository.
Free CVE requests
An advisory admin can request a CVE from GitHub. The identifier stays private until publication; GitHub says review usually takes up to 72 hours.
In practice: Kit cannot reserve or issue a CVE.
Private patch collaboration
Add the reporter to an advisory and work on a patch in a temporary private fork. Publishing the advisory can trigger Dependabot alerts in supported ecosystems.
In practice: The report, fix and public advisory remain with the code.
A report button on the repository
Enable private reporting on a public repository so researchers can submit a vulnerability from its security page.
In practice: Researchers reading the code do not need to find a separate company portal.
What Kit includes
Each report gets a deadline and a reminder, so none sits unanswered while you ship. Kit brings no researchers or managed triage.
Reports without researcher accounts
The intake form accepts reports with or without an email address. Researchers who provide an email can open their reports through an email link.
Researchers can report a problem without creating a password or sharing their identity.
Bounty records and masked payout details
Kit requests payout details after a bounty is approved and masks the saved details for staff. Each award enters a ledger that prevents edits to existing entries.
You can trace the award and its paperwork. Your team still sends the payment.
Researchers see missing payout paperwork
The report page shows whether an agreement, tax form or payout details are missing. Researchers accept the recorded agreement by clicking a button. Rejected tax forms include a reason.
Researchers can complete the missing step from their own report page.
The next action on each report
Kit highlights the current step: Assignment, Assessment, Decision or Bounty. Moving a report backward requires a comment. Idle reports trigger reminders, then an escalation to admins.
The report shows what needs doing, and its owner cannot mute the final escalation.
What Kit doesn't have
Check these limits before choosing Kit.
A report button beside the code
GitHub puts the reporting button on the public repository a researcher is already reading. People must discover your Kit form through security.txt or a link you publish.
Will we add it? Kit will not provide a researcher community. Keep GitHub private reporting enabled.
CVE issuance
GitHub is a CVE Numbering Authority and reviews CVE requests for free. Kit cannot reserve or issue a CVE.
Will we add it? No. Use a CNA such as GitHub for CVE requests.
Private patch collaboration
GitHub provides temporary private forks for a maintainer and reporter to work on a fix. Kit tracks reports and syncs issues to Jira or Linear; it does not host patches.
Will we add it? No. Patches belong in your code repository.
An advisory REST API
GitHub documents REST endpoints for repository advisories. Kit's security queue uses MCP and webhooks, with no REST API.
Will we add it? A security REST API is not scheduled.
How each works
Keep repository disclosure on GitHub. Use Kit for reports that need a separate company process.
Company-wide intake and response
Every $8 Kit seat includes the Security workflow: intake, triage, SLAs, bounty records, and exports. Your team validates findings and handles any payouts.
Report through patch and advisory
On a public repository, GitHub keeps the report, private patch, CVE request and advisory together. Publication can notify users through Dependabot in supported ecosystems.
Plans and costs
Kit
$8/seat/month
Security workflow included in the $8/seat/month Kit subscription
- Security workflow included in every seat
- 72-hour acknowledgment clock and a response-time dashboard
- Anonymous intake with a durable receipt link
- Append-only bounty ledger, W-9/W-8BEN collection
- Hosted security.txt with its expiry date kept current
GitHub private vulnerability reporting
Free on public repositories
Private vulnerability reporting is free on public repositories
- Free for public repositories on any GitHub plan
- CVE request review at no charge
- Temporary private forks for patches; CI is unavailable in those forks
- Documented advisory REST endpoints
- Dependabot alerts for supported dependencies
Plans and costs
Kit publishes its $8/seat/month price and includes the Security workflow. Your team handles triage and any bounty payments.
Adding Kit next to GitHub?
Consider Kit for:
- Reports about a hosted product or private assets
- Acknowledgment deadlines and recorded response times
- Reports from people without GitHub accounts
- Intake alongside GitHub Enterprise Server
- A published security.txt and intake form
Stay with GitHub alone if:
- Your reports concern public repositories on GitHub.com
- You need CVE requests and advisories
- Reporters help patch through private forks
- You want Dependabot alerts for supported dependencies
Data portability: GitHub advisories are accessible through its REST API. Keep repository reports on GitHub and start Kit records for reports about other assets.
$8€6,9929,99 zł£5.99 per seat, per month
Get started free