Skip to main content

Concepts for vulnerability reporting and management

Learn core concepts relating to vulnerability reporting and management on GitHub.

About the GitHub Advisory database

The GitHub Advisory Database contains a list of known security vulnerabilities and malware, grouped in three categories: GitHub-reviewed advisories, unreviewed advisories, and malware advisories.

About global security advisories

Global security advisories live in the GitHub Advisory Database, a collection of CVEs and GitHub-originated advisories affecting the open source world. You can contribute to improving global security advisories.