New fields for SecurityAdvisory GraphQL API

You can now read more of the GitHub Advisory Database directly from the GraphQL API without falling back to the REST API.

The SecurityAdvisory object gained five new fields:

  • cveId: The advisory’s CVE identifier.
  • sourceCodeLocation: A link to the affected source code relevant to the advisory.
  • githubReviewedAt: When GitHub reviewed the advisory.
  • nvdPublishedAt: When the National Vulnerability Database (NVD) published its record.
  • repositoryAdvisoryUrl: A link to the linked repository security advisory when there is one.

The securityAdvisories query also gained two new filters, severities and isWithdrawn, so you can narrow results on the server instead of downloading everything and filtering it yourself. They work alongside the filters you already use, such as classification, identifier, EPSS, and published or updated since.

This means fewer round trips, one authentication path, and one rate limit budget for integrations that read advisory data. It also makes it easier to build things like severity-based triage feeds, withdrawn advisory audits, and tracking of how quickly advisories move from NVD publication to GitHub review.

These changes are additive and read-only, so your existing queries keep working.

Learn more in the GraphQL API documentation and share your feedback.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论