2020-06-23 00:09:42 +05:30
---
stage: Plan
group: Project Management
2022-11-25 23:54:43 +05:30
info: To determine the technical writer assigned to the Stage/Group associated with this page, see https://about.gitlab.com/handbook/product/ux/technical-writing/#assignments
2020-06-23 00:09:42 +05:30
---
2021-09-30 23:02:18 +05:30
# Confidential issues **(FREE)**
2017-08-17 22:00:37 +05:30
2021-09-30 23:02:18 +05:30
Confidential issues are [issues ](index.md ) visible only to members of a project with
2017-08-17 22:00:37 +05:30
[sufficient permissions ](#permissions-and-access-to-confidential-issues ).
Confidential issues can be used by open source projects and companies alike to
keep security vulnerabilities private or prevent surprises from leaking out.
2022-04-04 11:22:00 +05:30
## Make an issue confidential
2017-08-17 22:00:37 +05:30
2022-04-04 11:22:00 +05:30
You can make an issue confidential when you create or edit an issue.
2017-08-17 22:00:37 +05:30
When you create a new issue, a checkbox right below the text area is available
2023-01-13 00:05:48 +05:30
to mark the issue as confidential. Check that box and select **Create issue**
to create the issue. For existing issues, edit them, check the
confidential checkbox and select **Save changes** .
2017-08-17 22:00:37 +05:30
2022-04-04 11:22:00 +05:30
When you create a confidential issue in a project, the project becomes listed in the **Contributed projects** section in your [profile ](../../profile/index.md ). **Contributed projects** does not show information about the confidential issue; it only shows the project name.
2022-10-11 01:57:18 +05:30
data:image/s3,"s3://crabby-images/81235/81235cbd8e99d34cce87914f6b8de868712c3aa1" alt="Creating a new confidential issue "
2017-08-17 22:00:37 +05:30
2022-04-04 11:22:00 +05:30
## Modify issue confidentiality
2017-08-17 22:00:37 +05:30
2018-03-17 18:26:18 +05:30
There are two ways to change an issue's confidentiality.
2021-03-08 18:12:59 +05:30
The first way is to edit the issue and toggle the confidentiality checkbox.
After you save the issue, the confidentiality of the issue is updated.
2018-03-17 18:26:18 +05:30
2022-07-23 23:45:48 +05:30
The second way is to locate the **Confidentiality** section in the sidebar and select
2018-03-17 18:26:18 +05:30
**Edit**. A popup should appear and give you the option to turn on or turn off confidentiality.
| Turn off confidentiality | Turn on confidentiality |
| :-----------: | :----------: |
2022-07-23 23:45:48 +05:30
| data:image/s3,"s3://crabby-images/c7e06/c7e0606c0e850a4b11baf33dd9ea5933a1325ec5" alt="Turn off confidentiality " | data:image/s3,"s3://crabby-images/2959e/2959eb0a59593015e67b0e20add115794fe5458c" alt="Turn on confidentiality " |
2017-08-17 22:00:37 +05:30
Every change from regular to confidential and vice versa, is indicated by a
2022-10-11 01:57:18 +05:30
system note in the issue's comments:
2017-08-17 22:00:37 +05:30
2022-10-11 01:57:18 +05:30
data:image/s3,"s3://crabby-images/0dbe4/0dbe460b89c1ebfe6a4d027cd1360ef70ae4fbbb" alt="Confidential issues system notes "
- **{eye-slash}** The issue is made confidential.
- **{eye}** The issue is made public.
2017-08-17 22:00:37 +05:30
2022-04-04 11:22:00 +05:30
When an issue is made confidential, only users with at least the Reporter role
2022-01-26 12:08:38 +05:30
for the project have access to the issue.
Users with Guest or [Minimal ](../../permissions.md#users-with-minimal-access ) roles can't access
the issue even if they were actively participating before the change.
2022-04-04 11:22:00 +05:30
## Confidential issue indicators
2017-08-17 22:00:37 +05:30
There are a few things that visually separate a confidential issue from a
2022-10-11 01:57:18 +05:30
regular one. In the issues index page view, you can see the confidential (**{eye-slash}**) icon
2021-10-27 15:23:28 +05:30
next to the issues that are marked as confidential:
2017-08-17 22:00:37 +05:30
data:image/s3,"s3://crabby-images/5514a/5514a6ac7002fd06c90a5a0349f457f34a5bae8c" alt="Confidential issues index page "
2021-03-08 18:12:59 +05:30
If you don't have [enough permissions ](#permissions-and-access-to-confidential-issues ),
you cannot see confidential issues at all.
2017-08-17 22:00:37 +05:30
---
2022-10-11 01:57:18 +05:30
Likewise, while inside the issue, you can see the confidential (**{eye-slash}**) icon right next to
2021-03-08 18:12:59 +05:30
the issue number. There is also an indicator in the comment area that the
2017-08-17 22:00:37 +05:30
issue you are commenting on is confidential.
data:image/s3,"s3://crabby-images/aebb1/aebb130567d560c7066630728fa7b53298e352ef" alt="Confidential issue page "
2018-03-17 18:26:18 +05:30
There is also an indicator on the sidebar denoting confidentiality.
| Confidential issue | Not confidential issue |
| :-----------: | :----------: |
| data:image/s3,"s3://crabby-images/ecd87/ecd87ff4e28e26b1403aad750e64542e76547b4a" alt="Sidebar confidential issue " | data:image/s3,"s3://crabby-images/9dfed/9dfede2d5332f25deea363b381640b8d1a30970d" alt="Sidebar not confidential issue " |
2021-10-27 15:23:28 +05:30
## Merge requests for confidential issues
2022-04-04 11:22:00 +05:30
Although you can create confidential issues (and make existing issues confidential) in a public project, you cannot make confidential merge requests.
Learn how to create [merge requests for confidential issues ](../merge_requests/confidential.md ) that prevent leaks of private data.
2021-10-27 15:23:28 +05:30
2017-08-17 22:00:37 +05:30
## Permissions and access to confidential issues
There are two kinds of level access for confidential issues. The general rule
is that confidential issues are visible only to members of a project with at
2022-04-04 11:22:00 +05:30
least the Reporter role. However, a guest user can also create
2017-08-17 22:00:37 +05:30
confidential issues, but can only view the ones that they created themselves.
2022-07-23 23:45:48 +05:30
Users with the Guest role or non-members can also read the confidential issue if they are assigned to the issue.
When a Guest user or non-member is unassigned from a confidential issue,
they can no longer view it.
2017-08-17 22:00:37 +05:30
Confidential issues are also hidden in search results for unprivileged users.
2022-04-04 11:22:00 +05:30
For example, here's what a user with the Maintainer role and the Guest role
2021-09-04 01:27:46 +05:30
sees in the project's search results respectively.
2017-08-17 22:00:37 +05:30
2021-12-11 22:18:48 +05:30
| Maintainer role | Guest role |
2021-09-04 01:27:46 +05:30
|:---------------------------------------------------------------------------------------|:---------------------------------------------------------------------------------|
2021-03-08 18:12:59 +05:30
| data:image/s3,"s3://crabby-images/321a5/321a596453409336045de0c5ac3310945cb5e194" alt="Confidential issues search by maintainer " | data:image/s3,"s3://crabby-images/78c8c/78c8cbf85b056175b1f5ad7a9d50276fcd63050a" alt="Confidential issues search by guest " |
2019-10-12 21:52:04 +05:30
2022-01-26 12:08:38 +05:30
## Related topics
2019-10-12 21:52:04 +05:30
2021-10-27 15:23:28 +05:30
- [Merge requests for confidential issues ](../merge_requests/confidential.md )
- [Make an epic confidential ](../../group/epics/manage_epics.md#make-an-epic-confidential )
2022-07-16 23:28:13 +05:30
- [Add an internal note ](../../discussions/index.md#add-an-internal-note )
2021-10-27 15:23:28 +05:30
- [Security practices for confidential merge requests ](https://gitlab.com/gitlab-org/release/docs/blob/master/general/security/developer.md#security-releases-critical-non-critical-as-a-developer ) at GitLab