
GitHub Advisory Database
Threat Intelligence- Overview
- Setup
- Data & mappings
- Operations & API
- Changelog
The GitHub Advisory Database connector syncs the global GitHub Advisory Database into Brinqa. It covers every GitHub-reviewed security advisory (GHSA) across all supported ecosystems — npm, pip, Maven, NuGet, RubyGems, Go, Composer, Rust, Erlang, Pub, Swift and GitHub Actions — and can optionally include unreviewed and malware advisories.
Each advisory is synced with its identifiers (GHSA, CVE), severity, CVSS v3 and v4 scoring, EPSS probability and percentile, CWE weaknesses, references and lifecycle dates. Every affected package is synced as its own record with its vulnerable version ranges, first patched versions and vulnerable functions, linked back to the advisory.
Use it as an advisory catalog to enrich Dependabot, Snyk and other open-source (SCA) findings with GitHub's severity, EPSS and CWE data, including advisories that are not in the NVD.
This is a public knowledge-base connector: it does not read anything from your own GitHub organizations or repositories. To sync Dependabot, code scanning or secret scanning alerts, use the GitHub connector.
Data retrieved from GitHub Advisory Database
| Connector Object | Required | Maps to Data Model |
|---|---|---|
| Security Advisory | Yes | Security Advisory |
| Vulnerable Package | Yes | Package |
Model relationships
For detailed steps on how to view the data retrieved from GitHub Advisory Database in the Brinqa Platform, see How to view your data.
Connection settings
When setting up a data integration, select GitHub Advisory Database from the Connector dropdown and provide the following:
| Setting | Required | Default | Description |
|---|---|---|---|
| API URL | No | https://api.github.com | GitHub REST API URL. Defaults to https://api.github.com |
| Access token | No | — | GitHub personal access token (classic or fine-grained). No scopes are required because the advisory database is public. The token is optional but strongly recommended: unauthenticated requests are limited to 60 per hour, which is not enough for a full sync. |
| Page size | No | 100 | Maximum number of advisories to get per API request. Must be between 1 and 100 |
| Maximum retries | No | 5 | Maximum number of times a failed or rate-limited request is retried |
Authentication
Method
Optional bearer token. The advisory database is public, so the connector works without credentials, but GitHub limits unauthenticated requests to 60 per hour — not enough for a full sync of roughly 25,000 reviewed advisories. A token raises the limit to 5,000 requests per hour.
Any GitHub personal access token works (classic or fine-grained). No scopes or repository permissions are required.
Endpoint
| Method | URL |
|---|---|
GET | https://api.github.com/advisories |
Request Headers
| Header | Value |
|---|---|
Authorization | Bearer <token> (only sent when a token is configured) |
Accept | application/vnd.github+json |
X-GitHub-Api-Version | 2022-11-28 |
User-Agent | BrinqaGitHubAdvisoryConnector/<version> |
Sample Error Response
{
"message": "Bad credentials",
"documentation_url": "https://docs.github.com/rest",
"status": "401"
}
Usage
When a token is configured, every request carries it as a bearer token:
Authorization: Bearer <token>
The connection test requests a single advisory (GET /advisories?per_page=1). An invalid token fails the test with Bad credentials.
Rate Limits
When GitHub reports that the primary rate limit is exhausted (403 or 429 with x-ratelimit-remaining: 0), the connector waits until the time in x-ratelimit-reset and retries. For a secondary rate limit it waits for the Retry-After interval, or 60 seconds when GitHub sends a secondary-rate-limit error without one. Retries are bounded by the maxRetries setting.
Sync Behavior
Syncs are incremental. On the first run the connector fetches every advisory of the configured type. After that it passes the sync token as modified=>={since}, so each run fetches only advisories that were published or updated since the previous sync, including advisories that were withdrawn in the meantime.
Security Advisory and Vulnerable Package are built from the same API response. Within one sync transaction, the first model to run fetches the advisories and caches them in a local store; the second model reads from that store instead of calling the API again.
How to obtain GitHub Advisory Database credentials
Obtain the required credentials from your GitHub Advisory Database administrator or the GitHub Advisory Database admin console, then enter them in the connection settings above.
Attribute mappings
Expand the sections below to view the mappings between the source and the Brinqa data model attributes:
Security Advisory
| Source Field Name | SDM Attribute |
|---|---|
credits[].user.login, credits[].type | CREDITS |
cve_id, identifiers[type=CVE].value | CVE_IDS |
cve_id, identifiers[type=CVE].value | CVE_RECORDS |
cvss_severities.cvss_v3.vector_string | CVSS_V3_VECTOR |
cvss_severities.cvss_v3.vector_string | CVSS_V3_BASE_SCORE |
cvss_severities.cvss_v3.vector_string | CVSS_V3_SEVERITY |
cvss_severities.cvss_v3.vector_string | CVSS_V3_TEMPORAL_SCORE |
cvss_severities.cvss_v3.vector_string | CVSS_V3_ATTACK_VECTOR |
cvss_severities.cvss_v3.vector_string | CVSS_V3_ATTACK_COMPLEXITY |
cvss_severities.cvss_v3.vector_string | CVSS_V3_PRIVILEGES_REQUIRED |
cvss_severities.cvss_v3.vector_string | CVSS_V3_USER_INTERACTION |
cvss_severities.cvss_v3.vector_string | CVSS_V3_SCOPE |
cvss_severities.cvss_v3.vector_string | CVSS_V3_CONFIDENTIALITY_IMPACT |
cvss_severities.cvss_v3.vector_string | CVSS_V3_INTEGRITY_IMPACT |
cvss_severities.cvss_v3.vector_string | CVSS_V3_AVAILABILITY_IMPACT |
cvss_severities.cvss_v3.vector_string | CVSS_V3_EXPLOIT_CODE_MATURITY |
cvss_severities.cvss_v3.vector_string | CVSS_V3_REMEDIATION_LEVEL |
cvss_severities.cvss_v3.vector_string | CVSS_V3_REPORT_CONFIDENCE |
cvss_severities.cvss_v4.vector_string | CVSS_V4_VECTOR |
cvss_severities.cvss_v4.vector_string | CVSS_V4_BASE_SCORE |
cvss_severities.cvss_v4.vector_string | CVSS_V4_THREAT_SCORE |
cvss_severities.cvss_v4.vector_string | CVSS_V4_ENVIRONMENTAL_SCORE |
cvss_severities.cvss_v4.vector_string | CVSS_V4_OVERALL_SCORE |
cvss_severities.cvss_v4.vector_string | CVSS_V4_SEVERITY |
cvss_severities.cvss_v4.vector_string | CVSS_V4_ATTACK_VECTOR |
cvss_severities.cvss_v4.vector_string | CVSS_V4_ATTACK_COMPLEXITY |
cvss_severities.cvss_v4.vector_string | CVSS_V4_ATTACK_REQUIREMENTS |
cvss_severities.cvss_v4.vector_string | CVSS_V4_PRIVILEGES_REQUIRED |
cvss_severities.cvss_v4.vector_string | CVSS_V4_USER_INTERACTION |
cvss_severities.cvss_v4.vector_string | CVSS_V4_VULNERABLE_SYSTEM_CONFIDENTIALITY_IMPACT |
cvss_severities.cvss_v4.vector_string | CVSS_V4_VULNERABLE_SYSTEM_INTEGRITY_IMPACT |
cvss_severities.cvss_v4.vector_string | CVSS_V4_VULNERABLE_SYSTEM_AVAILABILITY_IMPACT |
cvss_severities.cvss_v4.vector_string | CVSS_V4_SUBSEQUENT_SYSTEM_CONFIDENTIALITY_IMPACT |
cvss_severities.cvss_v4.vector_string | CVSS_V4_SUBSEQUENT_SYSTEM_INTEGRITY_IMPACT |
cvss_severities.cvss_v4.vector_string | CVSS_V4_SUBSEQUENT_SYSTEM_AVAILABILITY_IMPACT |
cvss_severities.cvss_v4.vector_string | CVSS_V4_EXPLOIT_MATURITY |
cvss_severities.cvss_v4.vector_string | CVSS_V4_SAFETY |
cvss_severities.cvss_v4.vector_string | CVSS_V4_AUTOMATABLE |
cvss_severities.cvss_v4.vector_string | CVSS_V4_RECOVERY |
cvss_severities.cvss_v4.vector_string | CVSS_V4_VALUE_DENSITY |
cvss_severities.cvss_v4.vector_string | CVSS_V4_VULNERABILITY_RESPONSE_EFFORT |
cvss_severities.cvss_v4.vector_string | CVSS_V4_PROVIDER_URGENCY |
cwes[].cwe_id | CWE_IDS |
cwes[].cwe_id | WEAKNESSES |
cwes[].name | CWE_NAMES |
description | DESCRIPTION |
epss.percentage | EPSS_SCORE |
epss.percentile | EPSS_PERCENTILE |
| ghsa_id | UID |
| github_reviewed_at | GITHUB_REVIEWED_AT |
| html_url | URL |
identifiers[].value | IDENTIFIERS |
| nvd_published_at | NVD_PUBLISHED_AT |
| published_at | PUBLISHED_DATE |
references[] | REFERENCES |
| repository_advisory_url | REPOSITORY_ADVISORY_URL |
severity | SOURCE_SEVERITY |
severity | SEVERITY |
severity | SEVERITY_SCORE |
| source_code_location | SOURCE_CODE_LOCATION |
summary | NAME |
type | TYPE |
| updated_at | SOURCE_LAST_MODIFIED |
url | API_URL |
vulnerabilities[].first_patched_version | PATCH_AVAILABLE |
vulnerabilities[].package | AFFECTED |
vulnerabilities[].package.ecosystem | ECOSYSTEMS |
| withdrawn_at | STATUS |
| withdrawn_at | WITHDRAWN_AT |
| — | LAST_CAPTURED |
Vulnerable Package
| Source Field Name | SDM Attribute |
|---|---|
| ghsa_id | SECURITY_ADVISORIES |
ghsa_id, vulnerabilities[].package.ecosystem, vulnerabilities[].package.name | UID |
vulnerabilities[].first_patched_version | FIXED_VERSION |
vulnerabilities[].package.ecosystem | ECOSYSTEM |
vulnerabilities[].package.name | NAME |
vulnerabilities[].vulnerable_functions[] | VULNERABLE_FUNCTIONS |
vulnerabilities[].vulnerable_version_range | AFFECTED_VERSION |
| — | CATEGORIES |
| — | LAST_CAPTURED |
Operations & API
Expand each connector object to see its operation options, delta-sync behavior, and the API it uses. See connector operation options for how to apply operation options (keys and values are case-sensitive).
Security Advisory
Operation options
| Option | Type | Default | Description |
|---|---|---|---|
type | String | reviewed | Advisory type to sync: reviewed, unreviewed or malware |
ecosystem | String | — | Only sync advisories affecting one ecosystem, e.g. npm, pip, maven, nuget, rubygems, go, composer, rust, erlang, pub, swift, actions |
pageSize | Integer | Configured pageSize | Advisories per request (1–100). A value outside that range fails the sync with a clear error |
Delta sync
Supported. The connector performs an incremental (delta) sync via the since sync token, filtering on modified.
API
- Type: REST endpoint · Endpoint:
GET /advisories - Default filters:
type=reviewed
- GitHub reports
unknownseverity for advisories it has not scored. These keepSOURCE_SEVERITY = unknownbut have noSEVERITYorSEVERITY_SCORE, so they are not counted as a real severity level. - CVSS metrics are parsed from the vectors in
cvss_severities. GitHub does not publish CVSS v2, so theCVSS_V2_*attributes in the schema stay empty. The legacy top-levelcvssfield repeatscvss_severities.cvss_v3and is not mapped separately. - Withdrawn advisories are still synced, with
STATUS = withdrawnandWITHDRAWN_ATset, so records that were previously synced as active are updated rather than left stale.
Vulnerable Package
Operation options
| Option | Type | Default | Description |
|---|---|---|---|
type | String | reviewed | Advisory type to sync: reviewed, unreviewed or malware |
ecosystem | String | — | Only sync packages from advisories affecting one ecosystem, e.g. npm, pip, maven |
pageSize | Integer | Configured pageSize | Advisories per request (1–100). A value outside that range fails the sync with a clear error |
Delta sync
Supported. The connector performs an incremental (delta) sync via the since sync token, filtering on modified.
API
- Type: REST endpoint · Endpoint:
GET /advisories - Default filters:
type=reviewed
- Records are per advisory, so a package affected by several advisories (for example
npm:undici) appears once for each advisory. UseSECURITY_ADVISORIESto navigate to the advisory, andECOSYSTEMplusNAMEto group records for the same package. - Vulnerable Package reads from the same local store as Security Advisory within a sync transaction. If both models run in one transaction with different operation options, the model that runs second uses the advisories fetched by the first.
Changelog
The GitHub Advisory Database connector has undergone the following changes:
| Version | Description | Migration Steps |
|---|---|---|
| 3.0.0 | New Features - GitHub Advisory Database connector: A new connector that syncs the global GitHub Advisory Database into Brinqa — every GitHub-reviewed security advisory across npm, pip, Maven, NuGet, RubyGems, Go, Composer, Rust and the other supported ecosystems. Use it as an advisory catalog to enrich Dependabot, Snyk and other open-source findings with GitHub's severity, EPSS and weakness data, including advisories that have no NVD entry. - Security Advisory: One record per GHSA advisory with its GHSA and CVE identifiers, severity, CVSS v3 and v4 vectors and scores, EPSS probability and percentile, CWE identifiers and names, references, credits, and published, updated, reviewed, NVD-published and withdrawn dates. CVE and CWE identifiers are populated in CVE_RECORDS and WEAKNESSES, so advisories link to your existing CVE and Weakness records. Withdrawn advisories are synced with STATUS = withdrawn. - Vulnerable Package: One record per advisory and affected package, with the package ecosystem and name, every vulnerable version range, the first patched versions and any vulnerable functions GitHub lists, linked back to its advisory through SECURITY_ADVISORIES. - Advisory types and ecosystems: Reviewed advisories are synced by default. Set the type operation option to unreviewed or malware to sync those advisories instead, and the ecosystem option to limit a sync to one ecosystem. - Incremental sync: After the first full sync, each run fetches only advisories published or updated since the previous sync. - Optional authentication: The advisory database is public, so a token is not required. A GitHub personal access token with no scopes raises GitHub's limit from 60 to 5,000 requests per hour, which a full sync needs. When GitHub's rate limit is reached, the connector waits for it to reset and continues. | N/A |