Skip to main content

此版本的 GitHub Enterprise Server 已于以下日期停止服务 2026-03-17. 即使针对重大安全问题,也不会发布补丁。 为了获得更好的性能、更高的安全性和新功能,请升级到最新版本的 GitHub Enterprise。 如需升级帮助,请联系 GitHub Enterprise 支持

关于全球安全公告

全球安全公告包括影响开源领域的 CVE 和 GitHub 原创公告,这些公告位于 GitHub Advisory Database 中。

在本文中

About global security advisories

Global advisories live in the GitHub Advisory Database and are grouped into three categories:

  • GitHub-reviewed advisories are mapped to packages in ecosystems we support. We carefully review each advisory for validity and ensure that they contain a full description and both ecosystem and package information.
  • Unreviewed advisories are published automatically into the GitHub Advisory Database, directly from the National Vulnerability Database feed.
  • Malware advisories relate to vulnerabilities caused by malware and are exclusive to the npm ecosystem. We publish them automatically into the GitHub Advisory Database, directly from information provided by the npm security team.

注意

Dependabot doesn't generate Dependabot alerts for unreviewed and malware advisories.

Every repository advisory is reviewed by the GitHub Security Lab curation team for consideration as a global advisory. We publish security advisories for any of the ecosystems supported by the dependency graph to the GitHub Advisory Database.

Anyone can suggest improvements on any global security advisory. You can edit or add any detail, including additionally affected ecosystems, severity level or description of who is impacted. The GitHub Security Lab curation team will review the submitted improvements.

Next steps

Access advisories in the GitHub Advisory Database. See Browsing security advisories in the GitHub Advisory Database.