Skip to content

How GitHub maintains its advisory database #23167

Discussion options

You must be logged in to vote
  1. What are your sources for vulnerability data, e.g. NVD, OSS Index?

See the sources listed in our documentation: Browsing security vulnerabilities in the GitHub Advisory Database - GitHub Docs

  1. Do you have any process to discover open source vulnerabilities by yourselves, e.g. through monitoring bug repositories? If yes, is it possible to share with us a high level explanation of what you do?

Yes, though most of our time is spent on curation and helping maintainers report their advisories.

  1. When collecting vulnerability data from third-party databases (e.g. NVD), do you perform any curation and/or correction, e.g. discarding debated CVEs or correcting the affected version range? If…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants